Inside the underground market for AI access

Demand for AI has given rise to a booming illicit market where criminals hijack AI accounts and exploit free trial credits to resell access at a profit.

Acerca del autor

Jeremy Kirk

Director, Okta Threat Intelligence

09 septiembre 2026 Tiempo de lectura: ~

In April, a software architect opened his AI provider bill and did a double take: $25,000, for usage he never authorized. Another organization's tab came to nearly $1 million before the fraud was discovered and contained. Incidents like these are on the rise as criminals turn to new tricks like AI token hijacking to gain control over AI accounts and resell stolen access at a profit. 

Demand for AI has skyrocketed, and everyone wants access to the most capable frontier models. But as the bills come due and users come face to face with rising token costs, the incentive to steal access to AI rather than pay for it is rising right alongside the cost of AI

This friction has spawned a booming illicit market. Threat actors are stepping in to offer AI access at massive discounts, sometimes 70% to 90% off standard subscription prices. But how are they doing it?

Okta Threat Intelligence has spent the past several months investigating the underground AI economy, and what we found breaks down into two distinct schemes: fake account sign-ups and AI account takeover.

How cybercriminals hijack AI accounts

Account takeover isn’t new. But as the price of frontier models rises, compromised AI accounts have become incredibly valuable targets. This theft leaves enterprises and software architects footing the bill.

To hijack AI accounts, attackers don't necessarily need your username and password. Instead, they steal your skeleton keys: session tokens, which keep you logged in without having to repeatedly enter your password, and API keys that provide persistent access for machines.

If a hacker tricks a user into downloading malware—such as a trojanized version of a popular video game—they can infect the computer with infostealers. These malicious programs silently siphon session tokens and API keys right out of the browser.

By replaying a stolen session token using specialized "anti-detect" web browsers and proxy networks, an attacker can bypass the login screen entirely. They are effectively signed in without actually signing in, completely sidestepping traditional credential-based authentication and multi-factor authentication (MFA).

To understand the scope of this threat, we analyzed a dump of infostealer data released on a Telegram channel on August 2, 2026. The 7GB dataset contained logs from 5,871 infected machines spread across 162 countries.

The haul was illuminating. We found thousands of valid, unexpired session tokens for major tech and AI providers, alongside dozens of valid API keys stored in plain text. 

The breakdown below highlights the most frequent targets we found in this specific data dump, rather than the overall market popularity of each service. Because providers such as Google, Microsoft, and Amazon use single sign-on gateways, the figures represent the primary authentication tokens set by those services. 

The attackers also stole thousands of JSON Web Tokens (JWTs), another form of digital access badge. Concerningly, nearly 18% of these JWTs contained plaintext personal information, such as names, phone numbers, and email addresses, handing attackers the exact data they need for future phishing and social engineering schemes.

As seen in screenshots from underground forums, these cybercriminals don't bother to obfuscate what they’re doing. In fact, many vendors involved in the theft and resale of AI authentication secrets choose to explicitly advertise stolen session tokens along with software "checkers" that automatically verify if the data is still valid.

The free-trial exploitation behind discounted AI

Beyond the outright theft of active accounts, cybercriminals have found another highly profitable business model: weaponizing promotional offers. 

If you look on underground forums or messaging apps like Telegram, you can easily find advertisements for suspiciously cheap AI tokens. These gray market services promise unlimited tokens or flat-fee monthly plans for a fraction of the official price.

Many gray market AI providers use professional-looking, AI-designed websites to market their services. Because these sites look legitimate, some users may not immediately realize that buying these discounted tokens violates the AI provider’s terms of service.

 

To the buyer, it looks like a great deal. They pay in cryptocurrency, receive an API key, and route their prompts through the gray-market provider. But behind the scenes, these providers are fueling their businesses by exploiting free bonus credits and startup discounts offered by major cloud providers. 

For example, Poison Claude advertises cheap access to premium Anthropic models (including Opus 4.8 and Sonnet 4.6) by hoarding $100 bonus credits from Amazon Web Services (AWS). Prompts are passed from Poison Claude’s API to Anthropic, with the answers seamlessly returned to the customer. These services are in demand: A simple configuration error by the operators of Poison Claude revealed an exposed API route, showing they had nearly 900 active users taking advantage of the service.

Another gray market service, Ecomagent.in, claims it can offer unlimited tokens at discounted prices due to its use of startup credits. Google offers credits that reach up to $350,000 for AI startups, while Anthropic offers up to $100,000 in free credits for startups. By using armies of bots to automate fake account registrations, threat actors pool these credits together and secretly route their customers' prompts through these fraudulently obtained accounts.

In another case, Okta Threat Intelligence observed an AI video company that offered free trials. Over a one-month period this year, we logged over 105,000 brute-force attempts to sign up from just 251 IP addresses, largely originating from networks in Lebanon, Indonesia, and Thailand. The attackers used disposable email domains (like dakaka.org) and popular Chinese email services (like qq.com) to create synthetic identities at an industrial scale.

Users in China can’t directly access US frontier models like ChatGPT, Claude, or Gemini. These models are either banned or blocked by China or not offered by providers because of national security concerns. Based on our observations, we believe it’s highly probable that users based in China are circumventing regional restrictions. 

Top countries | Distinct IPS

Image

AI service signup fraud: Email domain analysis

Image

Outsmarting the underground AI economy

As frontier AI models become more powerful and expensive to run, the financial incentive to steal access rather than pay for it will only grow. And unauthorized use of stolen AI accounts carries a second, less obvious cost: When stolen AI access is used to carry out other malicious cyber activity, it becomes far harder for investigators to trace that activity back to its true source.

To counter this illicit market, we have a few recommendations: 

  • Monitor sessions continuously. Security teams should monitor for session token reuse through solutions like Okta’s Identity Threat Protection. ITP continuously monitors sessions for context changes that may indicate risks. Administrators can use a feature called Universal Logout to kill the sessions and those of supported apps in one action.

  • Cap and scope API keys. Set usage caps and IP allowlisting on API keys to limit usage if stolen. If an organization restricts account access to a known range of IP addresses, a stolen token used from anywhere else won't work.

  • Raise the cost of fake sign-ups: Implement phishing-resistant credentials like passkeys that can’t be farmed, shared, or bulk-provisioned. Okta Threat Intelligence has not yet observed passkeys used in any signup fraud campaign we track.

As frontier models become more central to business operations, the keys to access them become just as valuable as the data they process. It's time to guard them accordingly and ensure your AI investments benefit your business—not the underground economy.

For the full technical research, including defensive recommendations for security teams, read Free tokens for sale: How fake signups drive AI fraud and the related report Signing in without actually signing in on the Okta Threat Intelligence blog.

Acerca del autor

Jeremy Kirk

Director, Okta Threat Intelligence

Reciba nuestro boletín de identidad

Imagen del boletín de Okta