Leaked AWS Keys Expose Bedrock Models To Llmjacking Arabian Post
FortiGuard Labs disclosed on September 3 that it had analysed an AWS account compromise involving a long-lived Identity and Access Management access key carrying AdministratorAccess permissions. The stolen credential was used to create a new IAM user, subscribe to foundation models through AWS Marketplace and invoke those models, generating inference costs for the victim.
The incident illustrates a technique known as LLMjacking, in which attackers abuse valid cloud credentials to consume hosted large language model services without paying for them. Rather than stealing model weights or training data, the objective is to make another organisation's account fund expensive model usage, which can be consumed directly or resold to third parties.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment