In brief: Fraudsters hijack cloud starter credits from Anthropic, Google and Amazon to sell AI model access on the underground market well below market price – Okta recommends mandatory passkeys and short-lived OAuth tokens as a countermeasure.
Okta Threat Intelligence has uncovered a black market for language model access that is financed through mass-produced fake cloud accounts and their free starter credits. Access to models such as Claude, GPT and Gemini is resold there at discounts of 70 to 90 percent compared to the regular market price.
Security researchers Jeremy Kirk and Mathew Woodyard of Okta Threat Intelligence analyzed several services that buy or generate fake accounts at Anthropic, Google or Amazon en masse in order to obtain free starter credits. They then resell access to the underlying models well below market price, often with discounts of 70 to 90 percent. The report describes the service Poison Claude in the greatest detail: the provider pools hijacked AWS Bedrock accounts along with their starter credits and internally routes customer requests to these accounts, as the operator openly explains on its own website. Customers thereby gain access to models such as Opus 4.8 or Sonnet 4.6 and pay in cryptocurrencies. An exposed status route showed the researchers, at the time of the investigation, 881 registered and 872 active users of the service.
According to the report, a comparable model is pursued by the service Ecomagent.in, which offers access via Google’s Vertex AI platform and is likely exploiting the generous starter credit of up to 350,000 US dollars available to AI start-ups. As a third example, the researchers cite an AI video service for which more than 105,000 automated registration attempts from 251 IP addresses were recorded between 2023 and 2026, many of them via VPNs from Lebanon, Indonesia and Thailand. Both stolen and specially created test accounts for this service were subsequently sold on underground forums. Okta informed Cloudflare, Anthropic, Amazon and Google about the infrastructure it found prior to publication. Cloudflare subsequently displayed a phishing warning in front of the Poison Claude site, but left another associated domain untouched.
The finding is particularly relevant for CISOs with regard to their own API key management: static, permanently valid access keys held with cloud and AI providers form the actual commodity of this gray market. If such keys are obtained via compromised or fraudulently created accounts, financial damage can result from misuse, along with potential reputational risks if corporate accounts are abused to access models such as Claude or Gemini.
As the most effective countermeasure, the authors recommend mandatory passkeys at registration, since, unlike passwords, these cannot be generated in bulk through automation. In addition, they advise providers to rely on short-lived OAuth access tokens instead of permanently valid static API keys. For companies managing their own API keys with cloud AI providers, the resulting recommendation is to make passkeys mandatory in registration processes for new accounts, consistently implement key rotation, and monitor usage patterns for anomalies such as unusual redirects or volume spikes.
Source: www.it-daily.net · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.