Google Warns Stolen Developer Accounts Fuel Dark Web AI Discounts
Underground marketplaces are selling access to Claude, Gemini, and OpenAI models at steep markdowns funded by cloud credential theft and credit abuse.

Key takeaways
- Marketplace prices for compromised AI accounts across Claude, Gemini, and Cursor Pro more than doubled in 2026, according to Google Threat Intelligence Group.
- Illicit brokers are reselling API access to leading commercial models at discounts of up to 97% below official retail rates.
- Attackers harvest plaintext credentials directly from coding tools like Cline and Continue AI using infostealers such as ACRSTEALER.
- Intermediate proxies like 'Poison Claude' allow threat actors to read prompts, capture private source code, and modify responses in transit.
Underground prices for stolen developer accounts and commercial artificial intelligence credentials more than doubled in 2026, according to findings from the Google Threat Intelligence Group. The spike in underground acquisition costs coincides with a flourishing illicit market offering steep discounts of up to 97% on access to frontier models from Anthropic, Google, and OpenAI, as reported by the Financial Times via AI Weekly.
Threat actors are funding these steep discounts through credential theft, cloud hijacking, and promotional credit exploitation. Instead of paying official per-token prices or subscription fees, brokers steal authentication tokens from enterprise environments or systematically farm introductory credits, leaving victims and hosting providers to absorb the computational costs.
What Drives the Market for Stolen Developer Accounts
According to Google Cloud's GTIG AI Threat Tracker, the illicit market has expanded rapidly with both more buyers and more sellers operating across clandestine forums. Demand is heavily concentrated on access to Anthropic's Claude and Google's Gemini, alongside autonomous coding environments such as Cursor Pro and Devin.
To satisfy this demand, cybercriminals have retooled established information-stealing malware strains, including LUMMAC.V2, STEALC.V2, VIDAR, and ACRSTEALER, to target AI-specific developer assets, as detailed by FomoEra. Rather than limiting operations to scraping web browser cookies and session data, malware operators now sweep local project directories for plaintext credentials.
In May 2026, the operators behind ACRSTEALER deployed automated rules specifically targeting the secrets.json configuration file used by Cline (formerly Claude Dev) and the config.yaml file used by Continue AI. These local developer configuration files frequently store unencrypted API keys, giving attackers immediate programmatic access to enterprise AI accounts.

How Brokers Offer Steep Model Discounts
While underground brokers are paying more than double what they paid previously to purchase verified accounts from infostealer rings, end buyers on dark web storefronts see massive price cuts. Marketplaces list API and platform access at 70% to 90% below official costs, with peak discounts reaching 97%, as cited by FomoEra.
In an analysis published in August 2026, Okta threat researchers Jeremy Kirk and Mathew Woodyard examined a broker operating under the moniker Poison Claude, reported by AI Weekly. The operation advertised Anthropic's Opus 4.6, 4.7, and 4.8, along with Sonnet 4.6, charging buyers between 5% and 15% of Anthropic's standard per-token pricing—representing an 85% to 95% markdown. The operation served at least 881 registered users and processed payments in cryptocurrency.
Okta traced the Poison Claude infrastructure through a 7 GB infostealer log archive shared on a Telegram channel on August 2, 2026. The researchers found that the vendor populated its pool through two primary mechanisms: farming promotional welcome incentives, such as the $100 onboarding credit offered by AWS Bedrock, and deploying disposable accounts registered with synthetic identities.

LLMJacking and Cloud Resource Hijacking
Direct credential abuse frequently escalates into cloud-scale resource theft, known as LLMJacking. Threat actors hijack corporate cloud compute quotas to execute compute-heavy workloads without authorization, as documented by Google Cloud.
In one incident investigated by GTIG in April 2026, an adversary obtained an exposed GitHub personal access token belonging to a corporate developer. The attacker used the credential to breach the enterprise cloud tenant, enabled Gemini Enterprise, and provisioned high-performance compute instances featuring 48 virtual CPUs (vCPUs). To maintain persistent access, the intruder created an unauthorized cloud service account granted full editor privileges, channeling high-cost model inference bills directly to the victim organization.
Beyond infrastructure bills, illicit AI resale creates acute security liabilities for buyers. Because operations like Poison Claude act as reverse proxies between users and model providers, the operators intercept every interaction. Okta confirmed that proxy operators can read raw prompt inputs and model responses—including source code, enterprise contracts, and proprietary data—and possess the capability to manipulate model outputs in transit without the user's awareness.
Anthropic has similarly documented rogue intermediaries in its September 2026 threat report. One counterfeit Claude reseller, tracked by Anthropic as GTG-50021, silently rerouted client requests to an alternative back-end model while distributing client-side tools infected with credential-harvesting malware, according to FomoEra.
Supply Chain Exploitation and the Defensive Response
The illicit account trade integrates closely with broader software supply chain attacks. GTIG identified financially motivated cybercrime group UNC6780 (also known as TeamPCP), which has conducted widespread compromises across PyPI, npm, and Docker Hub since March 2026, as outlined in Google Cloud's report.
UNC6780 embedded its DUSTMAKER credential stealer into trojanized forks of legitimate Model Context Protocol (MCP) packages, including tiktoken_mcp, and inserted malicious code into public repositories such as azure-functions-mcp-extension. DUSTMAKER targets hidden directories created by AI coding assistants, such as .claude/, .cursor/, and .vscode/, planting malicious build scripts and prompt injections designed to make AI coding agents execute arbitrary commands while evading detection by endpoint software.
In response to these campaigns, Google reported that DeepMind has updated internal classifiers to harden Gemini against exploitation, while engineering teams regularly disrupt identified threat actor accounts and infrastructure. Anthropic head of threat intelligence Jacob Klein told CNBC that an entire illicit ecosystem has emerged around unauthorized model access, with Anthropic concluding that AI API keys and session tokens deserve the same protection as any production credentials.
Frequently asked questions
Why have dark web prices for AI developer accounts doubled?
High buyer demand for frontier models such as Claude and Gemini, as well as AI coding agents like Cursor Pro and Devin, has raised the value of valid enterprise tokens and cloud API keys on underground marketplaces.
How can sellers offer AI model access at discounts up to 97%?
Sellers rely on stolen credentials through LLMJacking—passing the computational bill to breached companies—or systematically abuse free promotional credits from cloud providers using disposable synthetic identities.
What risks do buyers face when purchasing discounted AI access?
Brokers operate intermediate proxy servers that can view, record, or sell all submitted prompts, proprietary source code, and outputs, and can secretly tamper with model responses or install malware on the buyer's system.
Sources
- GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AIGoogle Cloud · Sep 8, 2026
- Google: Underground AI Account Prices More Than Doubled in 2026AI Weekly · Sep 27, 2026
- Claude, Gemini y GPT con hasta 97% de descuento: el mercado negro de la IA que pagan otrosFomoEra · Sep 27, 2026
How this story was made: the newsroom picked it up from Google Search and Techmeme, gathered the full text of the sources above, and drafted it with AI assistance. Every factual claim was then checked against those sources before publishing (45 claims checked). Illustrations marked as AI-generated are not photographs. Spotted an error? Tell us.
Published September 27, 2026 at 07:43 UTC


