Threat · curated 6 Aug 2026
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
First reported paloaltonetworks.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Token jacking lets attackers offload their AI compute costs onto victims by stealing exposed API keys, turning leaked LLM credentials into a direct financial and operational risk for organizations running AI services.
Unit 42's "Token Jacking" report describes how cybercriminals steal AI API keys and abuse AI gateways to hijack victims' AI resources (LLMjacking-style abuse), running up costs and consuming compute on the victim's account. The write-up is categorized as malware and threat research covering the theft and misuse of AI tokens and credentials.