Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Entities

OpenRouter services

Incidents implicated systems

Incident 8982 Report
Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

2024-05-06

Attackers reportedly exploited stolen cloud credentials obtained through a vulnerable Laravel system (CVE-2021-3129) to allegedly abuse AI cloud services, including Anthropic’s Claude and AWS Bedrock, in a scheme referred to as “LLMjacking.” The attackers are said to have monetized access through reverse proxies, reportedly inflating victim costs to as much as $100,000 per day. Additionally, they allegedly bypassed sanctions, enabled LLM models, and evolved techniques to evade detection and logging.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

LLMjacking Attackers Exploiting Laravel

Incidents involved as Deployer
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

Entities engaging in Russian sanctions evasion

Incidents involved as Deployer
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

OAI Reverse Proxy Tool Creators

Incidents involved as Developer
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

LLMjacking Reverse Proxy Tool Creators

Incidents involved as Developer
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

Laravel users

Incidents Harmed By
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

Laravel CVE-2021-3129 users

Incidents Harmed By
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

Cloud LLM users

Incidents Harmed By
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

Cloud LLM service providers

Incidents Harmed By
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

OpenAI models

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

Mistral-hosted models

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

MakerSuite tools

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

GCP Vertex AI models

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

ElevenLabs services

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

Azure-hosted LLMs

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

AWS Bedrock-hosted models

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

Anthropic Claude (v2/v3)

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More
Entity

AI21 Labs models

Incidents implicated systems
  • Incident 898
    2 Reports

    Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 1420c8e