Skip to content
Monday, September 28, 2026
  • Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off
  • MIT’s Tiny Mechanical Neuron Signals a New Era for Ultra Low-Power AI Computing
  • PlayStation Plus September: 14 Games From Essential to Premium
  • Apple’s M6 Mac Mini Emulates a 600MHz Pentium II With Voodoo 3

The Protec Blog

Guarding Your Future, One Byte at a Time.

Contact Us
Latest
  • Home
  • Cybersecurity
  • Artificial Intelligence
    • AI Tools
    • AI Agents
    • AI Automation
    • AI Development
  • Technology
    • Blockchain
    • Green Tech
    • Business Technology
    • Neurotech
    • Internet of Things (IoT)
    • Technology Trends
    • Quantum Computing
    • Wireless Technology
    • Gaming Technology
  • Development
    • Software
      • Backend Development
      • Frontend Development
      • Mobile Development
    • Website
      • Web Hosting
      • Web Security
      • WordPress
  • Reviews
    • Software Reviews
    • Tech Reviews
    • Buying Guides
  • Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off
  • MIT’s Tiny Mechanical Neuron Signals a New Era for Ultra Low-Power AI Computing
  • PlayStation Plus September: 14 Games From Essential to Premium
  • Apple’s M6 Mac Mini Emulates a 600MHz Pentium II With Voodoo 3

The Protec Blog

Guarding Your Future, One Byte at a Time.

Contact Us
Latest
  • Home
  • Cybersecurity
  • Artificial Intelligence
    • AI Tools
    • AI Agents
    • AI Automation
    • AI Development
  • Technology
    • Blockchain
    • Green Tech
    • Business Technology
    • Neurotech
    • Internet of Things (IoT)
    • Technology Trends
    • Quantum Computing
    • Wireless Technology
    • Gaming Technology
  • Development
    • Software
      • Backend Development
      • Frontend Development
      • Mobile Development
    • Website
      • Web Hosting
      • Web Security
      • WordPress
  • Reviews
    • Software Reviews
    • Tech Reviews
    • Buying Guides
Latest
  • Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off

    Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off

    11 hours ago11 hours ago
  • MIT's Tiny Mechanical Neuron Signals a New Era for Ultra Low-Power AI Computing

    MIT’s Tiny Mechanical Neuron Signals a New Era for Ultra Low-Power AI Computing

    1 day ago1 day ago
  • PlayStation Plus September: 14 Games From Essential to Premium

    PlayStation Plus September: 14 Games From Essential to Premium

    1 day ago1 day ago
  • Apple's M6 Mac Mini Emulates a 600MHz Pentium II With Voodoo 3

    Apple’s M6 Mac Mini Emulates a 600MHz Pentium II With Voodoo 3

    2 days ago2 days ago
  • Google Gemini Can Now Call Businesses for You: Meet the New Call for Me AI Agent

    Google Gemini Can Now Call Businesses for You: Meet the New Call for Me AI Agent

    2 days ago2 days ago
  • Microsoft Copilot Becomes a Super App for Chat, Code and Agents

    Microsoft Copilot Becomes a Super App for Chat, Code and Agents

    3 days ago3 days ago
  • Bun Rewrote 535,000 Lines in Rust: Why JavaScript Developers Should Care

    Bun Rewrote 535,000 Lines in Rust: Why JavaScript Developers Should Care

    3 days ago3 days ago
  • AI Leaders Warn the UN: Could Humanity Lose Control of Advanced AI?

    AI Leaders Warn the UN: Could Humanity Lose Control of Advanced AI?

    3 days ago3 days ago
  • What Happens When AI Agents Get Permission to Run Your Business?

    What Happens When AI Agents Get Permission to Run Your Business?

    3 days ago3 days ago
  • Snapdragon 8 Elite Gen 6 vs Apple A20 Pro: 2nm Battle Begins

    Snapdragon 8 Elite Gen 6 vs Apple A20 Pro: 2nm Battle Begins

    3 days ago4 days ago
  • Home
  • Cybersecurity
  • Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off

  • Cybersecurity

Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off

Aaron Thomas11 hours ago11 hours ago011 mins
Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off

Premium artificial intelligence is becoming another commodity in the cybercrime economy. According to observations reported by Google Threat Intelligence Group, underground sellers (Dark Web Hackers) are advertising access sell on services such as Claude, Gemini and ChatGPT at discounts claimed to reach 97% below legitimate subscription prices. Accounts for AI-powered developer tools, including Cursor Pro and Devin, have also appeared in illicit marketplaces.

The eye-catching discounts are only part of the story. These listings show how quickly criminals adapt when a digital service becomes valuable to businesses, developers and consumers. Instead of attacking an AI provider or stealing a proprietary model, many sellers obtain working credentials, browser sessions or cloud access that lets someone use a legitimate account without authorization.

As of September 2026, the expanding market for dark web AI accounts illustrates a broader shift in cybersecurity. Organizations must now protect access to powerful AI models with the same care applied to email, source-code repositories, cloud consoles and financial systems. A compromised AI account can expose sensitive conversations and files while giving an attacker access to paid capabilities, higher usage limits and connected development environments.

Contents

  • 1. What Google Threat Intelligence Observed
  • 2. Why Steal AI Accounts When Subscriptions Are Affordable?
  • 3. Account Theft, Session Theft and LLMjacking Are Different
    • 3.1. Stolen AI accounts and credential theft
    • 3.2. Session-token theft
    • 3.3. LLMjacking
    • 3.4. Model theft and attacks on providers
  • 4. Demand Is Moving Beyond ChatGPT
  • 5. How Underground Sellers Create Recurring Access
  • 6. AI Access Is Now a Business Security Boundary
  • 7. How to Defend Against AI Account Hacking
  • 8. What to Do After Suspected AI Credential Theft
  • 9. Frequently Asked Questions
    • 9.1. Are dark web AI accounts really sold for 97% off?
    • 9.2. Is LLMjacking the same as stealing a ChatGPT account?
    • 9.3. Why are Claude, Gemini, Cursor Pro and Devin targeted?
    • 9.4. Does an illicit AI account listing mean the model provider was hacked?
    • 9.5. What is the strongest protection for AI accounts?
  • 10. The Bottom Line

What Google Threat Intelligence Observed

Google Threat Intelligence has documented an underground market in which threat actors promote unauthorized access to commercial AI services. Advertised products include stolen ChatGPT accounts, stolen Claude accounts, stolen Gemini accounts and compromised subscriptions for AI coding platforms.

Read more
5 FREE AI Tools to Boost Earnings in 2025

Some listings reportedly claim discounts of up to 97% compared with official prices. Those figures should be treated as seller claims or threat-intelligence observations, not as independently verified market prices. An illicit listing does not prove that access works, remains stable or belongs to the account type described. Criminal markets are filled with recycled credentials, short-lived sessions, shared accounts and outright scams.

Nevertheless, repeated listings matter. They indicate sustained demand for dark web AI model access and a supply chain capable of acquiring, testing and reselling compromised access. Sellers may check whether credentials still work, categorize accounts by service tier and offer limited replacement guarantees. That process turns AI account theft into inventory rather than a one-time intrusion.

Why Steal AI Accounts When Subscriptions Are Affordable?

A basic AI subscription may be inexpensive compared with traditional enterprise software, but price is not the only source of value. Buyers in an AI hacking marketplace may want to avoid identity checks, payment records, regional restrictions or links between their activity and a personal billing account. Even a modest monthly fee becomes significant when someone needs dozens or hundreds of accounts for automated workflows.

Compromised accounts may also provide benefits unavailable through a new entry-level subscription:

  • Higher usage limits: Established premium, team or enterprise accounts can support more prompts, larger context windows or advanced tools.
  • Stored payment value: Some accounts are connected to paid plans, API credits or organizational billing arrangements.
  • Trusted account history: Older accounts may encounter fewer onboarding restrictions than newly created identities.
  • Connected resources: AI services may be linked to cloud storage, code repositories, email, documents or development environments.
  • Sensitive data: Chat histories, uploaded files, custom instructions and saved projects may contain proprietary information.

This explains why AI credentials for sale can attract buyers even when legitimate subscriptions are readily available. The buyer is not merely purchasing a discount. The buyer may be acquiring anonymity, existing privileges, corporate-funded capacity or access to data belonging to the victim.

Account Theft, Session Theft and LLMjacking Are Different

Read more
8 Best AI Assistants 2025: Revolutionize Your Work

Several related terms are often used interchangeably in coverage of AI account cybercrime. Understanding the technical distinctions helps security teams choose effective controls.

Stolen AI accounts and credential theft

Traditional AI credential theft involves obtaining a username and password through phishing, malware, credential stuffing, infostealer logs or reuse of credentials exposed in another breach. ChatGPT account hacking, Claude account hacking and Gemini account hacking can all begin this way. If multifactor authentication is absent or weak, an attacker may sign in normally and change recovery details.

Session-token theft

A session token proves that a user has already authenticated. Malware that steals browser cookies may let an attacker hijack an active session without knowing the password and, in some cases, without completing MFA again. Changing a password does not always terminate every active token, which is why session revocation is essential during incident response.

LLMjacking

LLMjacking usually refers to the unauthorized use of cloud or API credentials to consume paid large language model resources. Rather than taking over a consumer-facing account, an attacker may steal an API key, cloud service credential or workload identity and run requests at the victim’s expense. The resulting bill can grow quickly if usage limits and alerts are poorly configured.

Model theft and attacks on providers

None of these scenarios necessarily means the underlying AI model has been stolen. Model theft involves obtaining proprietary weights, architecture details or other protected intellectual property. A direct attack against an AI provider’s infrastructure is also different from using credentials taken from an individual customer. Most dark web Claude accounts, dark web Gemini accounts and dark web ChatGPT accounts concern unauthorized customer access—not evidence that the providers’ core models were breached.

Demand Is Moving Beyond ChatGPT

ChatGPT’s popularity made it an early target, but underground demand now follows capability rather than brand recognition. Claude is attractive for long-document analysis, writing and coding workflows. Gemini can be valuable because of its integration with Google’s broader ecosystem. Depending on account configuration, compromised access may place AI tools close to email, documents, cloud storage or workplace data.

AI coding account theft is an especially important development. Cursor Pro stolen accounts may provide advanced code-completion and agentic development features, while Devin account hacking could expose project context or access to an AI software-engineering environment. Developer tools are valuable because they sit near source code, documentation, terminals and deployment workflows.

Attackers can use compromised AI access for research, translation, summarization, code generation, debugging and automation. Those are dual-use capabilities: they support legitimate productivity but can also accelerate reconnaissance, improve phishing text, process stolen data or assist with malicious scripts. Access to a model does not automatically bypass its safeguards, but criminals continually test combinations of accounts, prompts and external tools to make their operations faster.

How Underground Sellers Create Recurring Access

The market for stolen AI credentials resembles other access-broker businesses. Infostealer malware collects browser passwords, cookies and tokens from infected devices. Sellers or intermediaries validate the captured material, identify premium services and package working accounts for resale. Credential stuffing can generate additional inventory when victims reuse passwords across websites.

Because compromised access can disappear after a password reset or fraud review, sellers may rotate inventory or promise replacements. One account can sometimes be shared among several buyers until usage controls, location changes or simultaneous sessions trigger detection. This model allows criminals to repeatedly monetize access while shifting the reliability risk to customers.

Enterprise accounts can be particularly valuable. A single compromised identity may provide AI access through centralized sign-on, expose internal prompts and reveal connected applications. If an organization has weak offboarding or keeps dormant accounts active, that access can persist long after the original theft.

AI Access Is Now a Business Security Boundary

AI model security is no longer limited to prompt injection, training-data questions or attacks on model infrastructure. Identity has become a central control. Employees routinely paste text, upload documents, connect repositories and ask AI systems to analyze business information. That makes an AI account both a productivity resource and a potential repository of sensitive data.

The risk grows as organizations deploy agents capable of taking actions rather than only generating text. An identity connected to ticketing, development or document systems may have permissions that extend beyond the AI platform itself. Security teams should inventory these connections and apply least privilege before an account becomes a route into other business resources.

These AI cybersecurity threats also complicate investigations. Unusual prompts may come from a legitimate employee, a hijacked browser session, a shared account or a stolen API key. Useful telemetry therefore includes sign-in events, device information, token creation, API consumption, geographic changes and activity in connected applications.

How to Defend Against AI Account Hacking

Effective AI account security combines identity controls, endpoint protection and usage monitoring. Organizations should prioritize the following measures:

  • Adopt phishing-resistant authentication: Use passkeys or hardware-backed security keys where supported. Traditional SMS codes and push approvals provide less protection against phishing and fatigue attacks. CISA provides additional guidance on multifactor authentication.
  • Centralize identity: Manage business AI services through approved enterprise identity providers and single sign-on. Central controls improve onboarding, offboarding, policy enforcement and rapid revocation.
  • Protect sessions: Limit session duration when appropriate, review active devices and revoke all sessions after suspected compromise. Password resets alone may not invalidate stolen cookies.
  • Secure employee devices: Use endpoint detection, prompt operating-system and browser updates, restrict unapproved extensions and investigate infostealer indicators quickly.
  • Eliminate password reuse: Require unique credentials stored in a reputable password manager. Monitor corporate addresses and domains for exposed credentials.
  • Control API secrets: Store keys in managed secret vaults, rotate them regularly and avoid embedding them in source code, scripts, tickets or chat conversations.
  • Set spending and usage alerts: Establish quotas, rate limits and anomaly notifications for API and cloud-based model consumption. Sudden activity can be an early sign of LLMjacking.
  • Review integrations: Audit which repositories, drives and workplace applications each AI account can reach. Remove unnecessary connectors and excessive permissions.
  • Prepare rapid revocation: Incident procedures should cover passwords, sessions, API keys, OAuth grants, connected applications and recovery methods.

Organizations should also discourage employees from purchasing unofficial access or sharing premium accounts. Cheap access may originate from a victim, expose the buyer to malware or disappear without warning. Approved procurement gives security teams visibility into ownership, billing and data-handling terms.

What to Do After Suspected AI Credential Theft

Begin by disabling or isolating the affected identity, then revoke active sessions and rotate passwords, API keys and recovery codes. Review recent prompts, file uploads, generated API keys, OAuth authorizations, billing activity and changes to account settings. If the account used federated login, examine the central identity provider for suspicious events.

Next, investigate the user’s device for infostealer malware. Restoring access before cleaning the endpoint can lead to immediate reinfection. Security teams should also inspect connected repositories, cloud storage and business applications, since the AI account may be only one part of a wider compromise.

Frequently Asked Questions

Are dark web AI accounts really sold for 97% off?

Google Threat Intelligence reporting has described underground advertisements claiming discounts as high as 97% for access to certain AI services. These are threat-actor claims, not independently verified prices. Listings may involve stolen credentials, hijacked sessions, shared accounts or scams, and access can stop working at any time.

Is LLMjacking the same as stealing a ChatGPT account?

No. A stolen ChatGPT account typically involves unauthorized access to a user-facing account. LLMjacking generally involves stolen cloud or API credentials used to consume paid model resources. Both create financial and data risks, but their detection signals and remediation steps differ.

Why are Claude, Gemini, Cursor Pro and Devin targeted?

Threat actors seek useful capabilities wherever they are available. Claude and Gemini support sophisticated analysis and generation, while Cursor Pro and Devin provide AI-assisted software-development functions. Premium accounts may also include higher limits, organizational billing or access to connected business resources.

Does an illicit AI account listing mean the model provider was hacked?

No. Most listings concern compromised customer credentials or sessions. That is different from stealing model weights, breaching provider infrastructure or directly defeating the security of the underlying model.

What is the strongest protection for AI accounts?

Phishing-resistant passkeys or hardware security keys provide a strong authentication foundation. They should be combined with secure devices, short-lived or well-monitored sessions, centralized identity management, API usage limits and a tested process for revoking every form of access.

The Bottom Line

The emergence of an AI account marketplace is a predictable consequence of valuable technology becoming embedded in daily work. Criminals do not need to steal an AI model to profit from it. Taking over a paid account, hijacking a browser session or abusing an API credential can provide immediate access to advanced capabilities and sensitive information.

For defenders, the lesson is clear: AI access belongs inside the organization’s core identity and cybersecurity program. Strong authentication, protected endpoints, controlled integrations, usage monitoring and rapid revocation can turn stolen AI credentials from a recurring criminal asset into short-lived, detectable access.

Tagged: Account Theft AI Account Security AI Accounts AI Credential Theft AI-Powered ChatGPT Claude Claude Security Credential Theft Dark Web Devin Gemini Google Threat Hacked Hackers LLMjacking OpenAI

Post navigation

Previous: MIT’s Tiny Mechanical Neuron Signals a New Era for Ultra Low-Power AI Computing

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

What Happens When AI Agents Get Permission to Run Your Business? What Happens When AI Agents Get Permission to Run Your Business?

What Happens When AI Agents Get Permission to Run Your Business?

Aaron Thomas3 days ago3 days ago 0
OpenAI Agent Breached Australia's Medicare Portal: Key Autonomous AI Security Risks OpenAI Agent Breached Australia's Medicare Portal: Key Autonomous AI Security Risks

OpenAI Agent Breached Australia’s Medicare Portal: Key Autonomous AI Security Risks

Aaron Thomas4 days ago4 days ago 0
ShinyHunters Claims FBI Hack via Oracle PeopleSoft Zero-Day ShinyHunters Claims FBI Hack via Oracle PeopleSoft Zero-Day

ShinyHunters Claims FBI Hack via Oracle PeopleSoft Zero-Day

Aaron Thomas4 days ago4 days ago 0
Scott Bessent's OpenAI-Hugging Face Hack Claims: What We Know Scott Bessent's OpenAI-Hugging Face Hack Claims: What We Know

Scott Bessent’s OpenAI-Hugging Face Hack Claims: What We Know

Ellie Adam6 days ago6 days ago 0

Highlights

  • Cybersecurity
  • Cybersecurity

Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off

6 days ago6 days ago
  • Emerging Technology
  • Emerging Technology

MIT’s Tiny Mechanical Neuron Signals a New Era for Ultra Low-Power AI Computing

6 days ago6 days ago
  • Gaming Technology
  • Gaming Technology

PlayStation Plus September: 14 Games From Essential to Premium

6 days ago6 days ago
  • Technology
  • Technology

Apple’s M6 Mac Mini Emulates a 600MHz Pentium II With Voodoo 3

6 days ago6 days ago

Trending News

Cybersecurity
Dark Web Hackers Sell Claude, Gemini and ChatGPT at 97% Off 01
11 hours ago11 hours ago
02
Emerging Technology
MIT’s Tiny Mechanical Neuron Signals a New Era for Ultra Low-Power AI Computing
03
Gaming Technology
PlayStation Plus September: 14 Games From Essential to Premium
04
Technology
Apple’s M6 Mac Mini Emulates a 600MHz Pentium II With Voodoo 3
05
Artificial Intelligence
Google Gemini Can Now Call Businesses for You: Meet the New Call for Me AI Agent
06
Artificial Intelligence
Microsoft Copilot Becomes a Super App for Chat, Code and Agents

Category Collection

Artificial Intelligence103 News
AWS2 News
Bitcoin2 News
Blockchain4 News
Design Tools10 News
Digital Courses3 News
Digital Currency2 News
E-Commerce3 News
EdTech8 News
Freelancing3 News
Mobile Technology30 News
Project Management3 News
SEO7 News

Subscription Form

  • Cryptocurrency
  • Software Development
  • Hardware
  • CRM
  • SaaS
  • Design & Media
  • Career & Earning
  • CRM
  • Buying Guides
  • Privacy Policy
  • Contact Us
The Protec Blogs 2026. Flag Counter Powered By Computer Zila.