{"id":26142,"date":"2026-09-21T13:06:02","date_gmt":"2026-09-21T21:06:02","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/someone-else-is-using-your-ai-3\/"},"modified":"2026-09-21T13:06:02","modified_gmt":"2026-09-21T21:06:02","slug":"someone-else-is-using-your-ai-3","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/someone-else-is-using-your-ai-3\/","title":{"rendered":"Someone Else Is Using Your AI"},"content":{"rendered":"<div class=\"Table-Content aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"blog-toc\">\n<div class=\"b3-blog-list__row\">\n<div class=\"b3-blog-list__column-left table-content-wrapper automatic\">\n<ul class=\"table-of-content\">\n<li class=\"header\"><img decoding=\"async\" alt=\"\" class=\"toc-icon\" src=\"\/content\/dam\/fortinet\/images\/toc-icon.jpg\"\/>Article Contents<\/li>\n<\/ul>\n<\/div>\n<div class=\"aem-GridColumn aem-GridColumn--default--8 b3-blog-list__column-right scrolling-content automatic\">\n<div class=\"b15-blog-meta__container text-container\">\n<span>By <\/span><br \/>\n<span class=\"b15-blog-meta__author\"><br \/>\n<a href=\"\/blog\/search?author=Akshat+Pradhan\">Akshat Pradhan<\/a><br \/>\n<\/span><br \/>\n<span class=\"b15-blog-meta__\"><br \/>\n<\/span><br \/>\n<span class=\"b15-blog-meta__date\"> | September 03, 2026<\/span>\n<\/div>\n<div class=\"C875-Disclaimer\">\n<\/div>\n<div class=\"raw-import\">\n<div class=\"text-container\"><\/div>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p style=\"\tmargin-left: 80.0px;\n\"><b>Affected Platforms: <\/b>Amazon Web Services (AWS), Amazon Bedrock<br \/>\n<b>Threat Type: <\/b>Cloud credential theft, AI\/LLM service hijacking (&#8220;LLMjacking&#8221;)<br \/>\n<b>Impacted Users: <\/b>Any organization with AWS accounts<br \/>\n<b>Impact: <\/b>Unauthorized consumption of paid foundation-model inference, resulting in direct financial loss; potential resale of hijacked model access<br \/>\n<b>Severity Level: <\/b>High<\/p>\n<p>Generative AI is quickly becoming one of the more lucrative uses for stolen cloud credentials. Attackers no longer need to set up crypto miners or exfiltrate data to cash in on a leaked IAM key. They can instead subscribe to foundation models through AWS Marketplace and resell inference access, a technique called <a aria-label=\"LLMjacking\" href=\"https:\/\/www.sysdig.com\/blog\/llmjacking-stolen-cloud-credentials-used-in-new-ai-attack\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"LLMjacking\"><i>LLMjacking<\/i><\/a>, first documented in 2024. FortiCNAPP recently investigated a case that shows how fast and mechanical that pivot has become.<\/p>\n<p>FortiGuard Labs recently analyzed a long-lived AWS IAM access key with administrator privileges that was used to create a new IAM identity, subscribe it to foundation models on AWS Marketplace, and begin invoking them.<\/p>\n<p>FortiCNAPP provides coverage against attacks like this through a combination of detections and LQL policies that span the identity compromise, credential issuance, and marketplace activity involved in such a chain.<\/p>\n<h2>LLMjacking: Attackers Want Your Model Access, Not Your Data<\/h2>\n<p>LLMjacking refers to the theft and abuse of access to hosted AI models, rather than the theft of model weights or training data. The attacker&#8217;s objective is simple: get another organization&#8217;s cloud account to pay for expensive, high-capability model inference, then either use that access directly or resell it.<\/p>\n<p>It&#8217;s attractive for a few structural reasons:<\/p>\n<ul>\n<li><b>Low tooling cost, high monetization.<\/b> The only prerequisite is a working cloud identity, typically a leaked access key, an exposed CI\/CD secret, or a stolen local credential.<\/li>\n<li><b>Fast time-to-abuse.<\/b> Once a cloud credential is exposed, attackers move in <a aria-label=\"The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub\" href=\"https:\/\/blog.gitguardian.com\/the-state-of-secrets-sprawl-2026\/\" rel=\"noopener noreferrer\" target=\"_blank\">minutes<\/a>, not days.<\/li>\n<li><b>Real money, fast.<\/b> Premium foundation-model invocation is not cheap at scale. <a aria-label=\"LLMjacking research\" href=\"https:\/\/www.sysdig.com\/blog\/llmjacking-stolen-cloud-credentials-used-in-new-ai-attack\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"LLMjacking research\">LLMjacking research<\/a> puts victim exposure at over $46,000 per day for a Claude 2.x-class inference and past $100,000 per day once attackers move to Claude 3 Opus. Some campaigns resell stolen access as a subscription &#8220;AI chatbot&#8221; service to third parties who have no idea the underlying compute is stolen, turning a single leaked key into recurring revenue.<\/li>\n<li><b>It hides in plain sight.<\/b> A Bedrock InvokeModel call from a compromised-but-valid IAM identity is, at the API level, indistinguishable from legitimate use. It is simply a cloud API used exactly as designed, with credentials that technically have permission to use it.<\/li>\n<li><b>The market has matured.<\/b> What began as opportunistic credential theft has evolved into a commercial supply chain. <a aria-label=\"Operation Bizarre Bazaar\" href=\"https:\/\/www.sysdig.com\/blog\/llmjacking-from-emerging-threat-to-black-market-reality\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"Operation Bizarre Bazaar\">&#8220;Operation Bizarre Bazaar&#8221;<\/a> cataloged more than 35,000 attack sessions and a marketplace reselling access to 30-plus LLM providers on Telegram and Discord. This is no longer opportunistic. It has been commoditized.<\/li>\n<\/ul>\n<h2>The Compromise We Observed<\/h2>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 1: Sequence of events in the compromise<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>An AWS account was compromised due to a leaked long-lived IAM access key with AdministratorAccess permissions. Using that access, the operator:<\/p>\n<ul>\n<li>Created a new IAM user.<\/li>\n<li>Subscribed to one or more foundation models through AWS Marketplace (CreateAgreementRequest\/AcceptAgreementRequest on agreement-marketplace.amazonaws.com).<\/li>\n<li>Invoked the subscribed foundation model(s), generating inference charges against the victim account.<\/li>\n<\/ul>\n<p>This class of attack typically includes an additional step to generate Bedrock service-specific credentials for the new identity via <a aria-label=\"AWS's long-term API key mechanism\" href=\"https:\/\/docs.aws.amazon.com\/bedrock\/latest\/userguide\/api-keys.html\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"AWS's long-term API key mechanism\">AWS&#8217;s long-term API key mechanism<\/a>. This is distinct from a standard IAM access key, as an alternative or to supplement invocations directly through the new user.<\/p>\n<h2>Recommendations for Defenders<\/h2>\n<p>Because LLMjacking uses valid credentials and legitimate cloud services, effective prevention and detection demand strong identity verification, thorough logging, and contextual analysis. The practices outlined below can assist organizations in minimizing their risk and spotting suspicious Bedrock activity more efficiently.<\/p>\n<ul>\n<li><b>Enable CloudTrail on every account.<\/b> It&#8217;s what turns a suspicious signal into a full picture: who created the identity, what credentials it issued, what it subscribed to, and in what order.<\/li>\n<li><b>Turn on Bedrock invocation logging<\/b> in addition to CloudTrail, where feasible. It&#8217;s off by default and captures request-level details that CloudTrail alone won&#8217;t capture.<\/li>\n<li><b>Treat long-lived, broad-scope IAM keys as tier-0 risk.<\/b> The entire chain in this incident depended on a single AdministratorAccess key that never expires. Prefer short-lived, role-assumed credentials wherever workloads allow it.<\/li>\n<li><b>Don&#8217;t assume &#8220;new AI service usage&#8221; is always benign or always malicious.<\/b> The right posture is corroboration. First-time Bedrock use in an account is only actionable when paired with a second signal, such as a new identity, an unfamiliar IP, enumeration behavior, or access-denied noise, not on its own.<\/li>\n<\/ul>\n<h2>Fortinet Protections<\/h2>\n<p><b>FortiCNAPP <\/b>(Lacework) ships detection coverage relevant to this attack chain:<\/p>\n<p><b>lacework-global-12: IAM Policy Change<\/b> *(High, on by default)*. Covers privilege-escalation actions such as attaching AdministratorAccess to an identity, the step that enabled everything downstream in this case.<\/p>\n<p><b>lacework-global-2037: Bedrock model invocation logging deleted<\/b> *(High, on by default)*. Flags an operator disabling Bedrock&#8217;s own audit trail, a defense-evasion step we watch for.<\/p>\n<p><b>lacework-global-2038: Bedrock invocation throttling exceptions<\/b> *(Medium, on by default)*. Fires on a Bedrock ThrottlingException: a per-event signal, not a volume threshold.<\/p>\n<p><b>lacework-global-2906: Marketplace agreement created or accepted<\/b> *(Medium, on by default)*. Flags CreateAgreementRequest\/AcceptAgreementRequest on agreement-marketplace.amazonaws.com, the actual subscription step in this chain.<\/p>\n<p><b>lacework-global-2907: IAM service-specific credential created or reset<\/b> *(Medium, on by default)*. Covers Bedrock&#8217;s service-specific credential mechanism directly.<\/p>\n<p><b>lacework-global-13: IAM Access Key Change<\/b> *(High, on by default)*. Covers traditional access-key creation and rotation. It does not cover Bedrock&#8217;s service-specific credentials, issued through a separate API call; that&#8217;s what 2907 closes.<\/p>\n<p><b>lacework-global-14: New AWS User Created<\/b> *(available, not enabled by default)*. We recommend that customers running AI workloads on AWS explicitly enable this.<\/p>\n<p><b>lacework-global-1999 through 2002, 2781: Bedrock configuration\/posture policies<\/b> *(available, not enabled by default)*. These detections flag issues such as Bedrock invocation logging being disabled at the configuration level, and require no CloudTrail integration to run. They ship outside our default compliance frameworks by design (only framework-member policies are auto-enabled), so they need explicit enablement or inclusion in a custom framework to surface in compliance reporting. We recommend turning them on for any account with Bedrock access.<\/p>\n<p>FortiCNAPP&#8217;s broader anomaly and threat detection also covers this technique. Together, this coverage spans the full chain: the initial privilege-escalation step, credential issuance, marketplace subscription, and invocation-time abuse.<\/p>\n<p><a aria-label=\"FortiGuard IP Reputation\" href=\"\/support\/support-services\/fortiguard-security-subscriptions\/ipreputation-antibot\" title=\"FortiGuard IP Reputation\">FortiGuard IP Reputation<\/a> and <a aria-label=\"Anti-Botnet Security Service\" href=\"\/support\/support-services\/fortiguard-security-subscriptions\/ipreputation-antibot\" title=\"Anti-Botnet Security Service\">Anti-Botnet Security Service<\/a> proactively block attacks by aggregating malicious source IP data from Fortinet\u2019s distributed network of global sensors, CERTs, MITRE, cooperative partners, and other trusted sources. This continuous intelligence enables up-to-date protection against hostile actors.<\/p>\n<p>For supplementary protection capabilities, refer to <a aria-label=\"Fortinet\u2019s product catalog\" href=\"\/products\">Fortinet\u2019s product catalog<\/a>.<\/p>\n<p>If you believe this or any other cybersecurity threat has impacted your organization, contact our Global <a aria-label=\"FortiGuard Incident Response Team\" href=\"https:\/\/www.fortiguard.com\/faq\/csirt-contact\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"FortiGuard Incident Response Team\">FortiGuard Incident Response Team<\/a> for assistance.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Affected Platforms: Amazon Web Services (AWS), Amazon Bedrock<br \/>\nThreat Type: Cloud credential theft, AI\/LLM service hijacking (&#8220;LLMjacking&#8221;)<br \/>\nImpacted Users: Any organization with AWS accounts<br \/>\nImpact: Unauthorized consumption of paid foundation-model inference, resulting in direct financial loss; potential resale of hijacked model access<br \/>\nSeverity Level: High<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10424,10378,32774],"tags":[],"class_list":["post-26142","post","type-post","status-publish","format-standard","hentry","category-fortinet","category-security","category-threats"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26142","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26142"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26142\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26142"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26142"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26142"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}