FortiGuard Labs documented an LLMjacking intrusion in which attackers used a leaked, long-lived AWS IAM access key with AdministratorAccess to create a new IAM user, subscribe to premium foundation models through AWS Marketplace, and run inference charges against the victim organization. The financial exposure can be substantial: abuse of Claude 2.x may exceed $46,000 per day, while Claude 3 Opus usage may exceed $100,000 per day.
The actors may create Amazon Bedrock service-specific API keys to conceal the activity and resell stolen model access through low-cost chatbot subscriptions promoted on Telegram and Discord. Because requests are made with valid AWS credentials, the abuse can resemble legitimate usage; organizations should eliminate long-lived privileged access keys in favor of short-lived assumed-role credentials, enable organization-wide CloudTrail and Bedrock invocation logging, and investigate new Bedrock activity alongside identity, IP, enumeration, and access-denied anomalies.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs documented attackers using a leaked long-lived AWS IAM key with AdministratorAccess to create an IAM user, subscribe to foundation models through AWS Marketplace, and run inference billed to the victim organization. The report said stolen model access can be resold through low-cost chatbot subscriptions and linked Operation Bizarre Bazaar to more than 35,000 attack sessions across over 30 LLM providers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.