97% Off Claude And GPT: Why Stolen AI Subscriptions Are Flooding The Dark Web

Somewhere in the darker corners of the web, top-shelf AI access is changing hands for the cost of a lunch deal, and the person selling it certainly didn’t foot the bill.

According to reports, Google’s Threat Intelligence Group has spotted underground marketplaces flogging unauthorised access to Anthropic, Google and OpenAI models at discounts hitting 97%. While official top-tier plans for tools like ChatGPT and Claude run up to $200 per user each month, cybercriminals are selling them on forums for pocket change.

Naturally those numbers come from the sellers and are not verified transactions, meaning plenty of listings turn out to be scams, hijacked multi-user accounts or dead credentials that burn out the moment security teams spot them. Even so, the trend points to a growing black market for AI access.

 

How Paid AI Access Ends Up On Sale

 

Google labels the hustle LLM-jacking, a trick where cybercriminals steal credentials or commandeer cloud servers to run models on someone else’s tab. John Hultquist, principal analyst at GTIG, has pointed out that these raids on AI accounts and raw computing have grown significantly this year.

The pipeline feeding these markets depends on familiar tricks. Infostealer malware and data dumps flood forums with credentials and API keys packaged as functional AI accounts. One notable operation named Bissa Scanner scraped login details for Anthropic, OpenAI, Google and other systems across tens of thousands of exposed configuration files according to Google research.

Stolen session tokens, cookies and OAuth permissions create another entry point. They grant unauthorised entry to active paid subscriptions without needing the original password, so the account behaves normally from the provider perspective until anomalous volume trips a defence system.

Meanwhile, the enterprise variant involves attackers infiltrating corporate servers or cloud setups tied to commercial AI tools, extracting free compute power or reselling the access while leaving the organisation to pay the invoice.

 

Why 97% Off Is The Giveaway

 

When a $200 subscription drops to about six dollars, nobody is running a charity drive. It points to a seller who hasn’t paid list price and is offloading compromised credentials or hijacked sessions.

The vendor listings give the game away. Some sellers advertise a connection guarantee or after-sales cover, promising replacement credentials if the provider blocks the account. It’s close to a subscription startup, built for a high-turnover criminal market.

The underground economy is quickly expanding. Google monitoring data shows a surge of active buyers and sellers swapping compromised AI accounts in 2026, while average street prices for those stolen setups have more than doubled over the past year. Buyers are particularly concentrated on Claude and Gemini credentials alongside specialized coding platforms like Cursor Pro and Devin.

 

 

Your Subscription Could Be On The Menu

 

The unfortunate reality for businesses is that the subscriptions floating around on the dark web might belong to them.

A stray infostealer hiding on a staff laptop or an API key left behind in an abandoned code repository is all it takes to put corporate AI access up for auction. GTIG research points to exposed configuration files as one source of stolen credentials.

Once those keys land in criminal hands, the invoice remains with the rightful owner. Attackers can carry out heavy workloads or policy-breaking queries that trigger sudden account bans, shock overage bills and messy compliance nightmares including corporate data leaking out through rogue prompts.

AI providers may struggle to tell legitimate traffic from hijacked sessions until afterwards. That leaves the victimised company scrambling to handle downtime and internal audits before it finds out who was using the account.

LLM-jacking goes beyond stolen logins too. In some cases, criminals breach cloud servers to host their own AI workloads, turning a victim’s hardware into a free computing cluster for third parties. Even an enterprise that hasn’t touched commercial AI can end up acting as an involuntary host for criminal infrastructure.

Ultimately the black market for AI operates on basic economics. Whenever demand for expensive and restricted technology outstrips what buyers want to pay, someone else’s credentials naturally turn into the discount route in.