← All posts / Meta

97% Off Claude: Inside the Dark Web's Booming Black Market for Stolen AI Access

A Financial Times report based on Google Threat Intelligence findings documents underground marketplaces reselling stolen access to Claude, Gemini and ChatGPT at discounts up to 97% — with prices for hijacked accounts more than doubling in 2026 as criminals chase cheap agentic compute.

97% Off Claude: Inside the Dark Web's Booming Black Market for Stolen AI Access

For years, the prized commodities of the criminal underground were credit card dumps, banking credentials, and ransomware affiliates. According to a Financial Times investigation published September 26 and drawing on findings from Google’s Threat Intelligence Group (GTIG), there is a new hottest product on the dark web: access to frontier AI models — Claude, Gemini, ChatGPT and their agentic siblings — resold at discounts of up to 97% off official pricing.

The FT report, anchored by GTIG’s ongoing threat tracking, describes a fast-maturing gray-to-black market in which hackers hijack AI accounts and cloud servers, harvest credentials at industrial scale, and resell the stolen capacity to buyers who want frontier-model intelligence without the frontier-model bill — or the identity trail.

What the market is selling

The inventory is broader than most security teams assume. According to the FT’s account of the GTIG data, dark web marketplaces are selling unauthorized access to leading AI models from Anthropic, Google and OpenAI at discounts of up to 97% off standard pricing. That is not a typo: a subscription or API tier that costs a legitimate customer hundreds of dollars a month can be had underground for pocket change, because the seller’s cost basis is zero — the access was stolen.

GTIG has separately noted that average underground prices for stolen Claude, Gemini and Cursor Pro accounts have more than doubled during 2026. In normal markets, rising prices signal scarcity. Here they signal the opposite: demand is growing even faster than supply, because what buyers increasingly want is not a chatbot login but agentic capability — accounts and tokens that can drive autonomous, tool-using AI workloads around the clock.

The mechanics will be familiar to anyone who has tracked info-stealer ecosystems. Credential-harvesting malware families such as Lumma Stealer, Vidar and ACR Stealer have expanded their capabilities explicitly to target AI developer configurations — API keys sitting in .env files, OAuth tokens in local agent configs, session cookies for paid AI subscriptions. Each infected developer machine becomes a vending machine.

The reseller middlemen

A parallel ecosystem of reseller services, documented earlier this year by Okta Threat Intelligence and covered by IT Pro, shows how industrialized this has become. Operations like “Poison Claude” and Ecomagent.in abuse genuine promotional offers — free sign-up bonuses, startup credit programs like AWS Bedrock’s $100 introductory credit — to pool thousands of fresh accounts behind a single API endpoint.

The business model is brutally simple. “We add those accounts to our pool, your request is routed to a specific account under the hood (you don’t see this) and you get charged 5–15% of the official per-token price depending on the model,” one such service explained. Customers receive an Anthropic-compatible API key and a few environment variables; everything after that looks like a normal API call.

Okta’s researchers found the demand is heavily China-weighted, since Anthropic and OpenAI restrict access from mainland China. Chinese-language offerings on Taobao, Telegram and underground forums outnumber English-language ones — regional restrictions have created a durable arbitrage that smugglers are only too happy to fill.

There is a second, quieter revenue stream embedded in this architecture: when a gray-market service acts as a gateway proxy, the operator sees every prompt. That visibility turns stolen inference into a distillation pipeline — prompts and outputs can be harvested to train cheaper models — and it means every “bargain” customer is also leaking their data to a criminal intermediary.

Why prices are doubling: the agentic demand shock

The FT piece quotes John Hultquist, chief analyst at Google Threat Intelligence Group, describing a major increase in so-called LLM-jacking — criminals using stolen cloud and AI credentials to run workloads on someone else’s bill. But the deeper driver is the shift in what criminals need AI for.

GTIG’s September “From Prompting to Autonomy” threat tracker, a key source for the FT report, documented a financially motivated group that used an AI coding chatbot, a single prompt, and preconfigured markdown playbooks to plan, build and execute a mass credential-harvesting campaign in under six hours — autonomously managing vulnerability scanning, real-time troubleshooting and IP rotation without a human in the loop. Thousands of third-party credentials were compromised before the operation wound down.

That is the new unit economics of cybercrime: one operator, one prompt, thousands of compromises. And it runs on stolen compute. An autonomous agent burning tokens 24/7 on a legitimate subscription would trip rate limits and fraud detection almost immediately; a pool of thousands of hijacked accounts rotates the load invisibly. The more agentic the offense becomes, the more valuable stolen AI access is — which is exactly why underground prices doubled even as supply exploded.

From theft to extortion

The FT reporting also lands on a darker consequence flagged by GTIG: proprietary AI models themselves have become targets. Threat actors have been observed stealing models, skills, prompts, source code and AI research from healthcare, government and media victims — not just to use, but to ransom. A stolen, fine-tuned model represents months of proprietary work; extorting its owner with the threat of public release is a natural evolution of data-theft extortion into the AI era.

Some groups skip the frontier providers entirely. GTIG tracks actors like UNC6508 that compromise cloud environments to host local, open-weight models — capable, unmonitored, and invisible to the API-gated monitoring that providers rely on. The open-source ecosystem that fuels legitimate innovation simultaneously gives well-resourced criminals a way to operate with zero provider visibility.

What it means for defenders

Three implications stand out for security teams watching this market mature.

First, AI credentials are now crown-jewel secrets. An API key in a developer’s shell config is no longer a cost risk — it is hostile infrastructure. Teams should treat AI keys with the same controls as production database credentials: vaulting, rotation, per-key spend caps, and anomaly alerting on usage patterns.

Second, the victim pays twice. LLM-jacking victims absorb the fraudulent bill and become attack infrastructure — their accounts and IP reputation used to harm others. The indirect liability may eventually exceed the direct cost.

Third, the monitorability gap is widening. API-gated frontier models give providers at least a telemetry channel for misuse; local open-weight deployments give none. As GTIG itself argues, closing that gap requires enforceable industry-wide safety baselines for open-weight AI and coordinated platform policies against uncensored checkpoints — a policy fight that is only beginning.

The uncomfortable conclusion of the FT-GTIG picture is that the AI access gap is being arbitraged by criminals faster than by customers. Frontier labs price their models for enterprises; the underground prices them for everyone else. Until credential hygiene, fraud detection and regional-licensing frictions catch up, the hottest product on the dark web will stay in stock.

Sources

  • Financial Times — “Hackers hijack AI accounts and servers to fuel new cyber crime wave” (Sept 26, 2026)
  • Google Cloud Threat Intelligence Blog — GTIG AI Threat Tracker: “From Prompting to Autonomy – The Evolution of Adversarial AI”
  • The Hacker News — “Autonomous AI Agents Compromise Thousands of Credentials” (Sept 8, 2026)
  • IT Pro — “Cyber criminals are selling discount AI tokens on underground forums”
  • Computing — “Cyber criminals are stealing corporate AI models to ransom”