Hackers hijack AI accounts and servers to fuel new cyber crime boom - FT中文网
登录×
电子邮件/用户名
密码
记住我
请输入邮箱和密码进行绑定操作:
请输入手机号码,通过短信验证(目前仅支持中国大陆地区的手机号)。如果该手机号尚未注册,将自动创建 FT中文网账号。短信可能需要几分钟送达,验证码15分钟内有效,请耐心等待:
请您阅读我们的用户注册协议和隐私权保护政策,点击下方按钮即视为您接受。
FT商学院

Hackers hijack AI accounts and servers to fuel new cyber crime boom

Security researchers warn of surge in ‘LLM-jacking’ attacks targeting companies’ costly AI resources
00:00

{"text":[[{"start":7.52,"text":"Illicit access to AI models and computing power is fast becoming the hottest commodity in the cyber criminal underworld, as hackers seek to harness expensive large language models for extortion, warfare and espionage."}],[{"start":20.12,"text":"John Hultquist, chief analyst for Google Threat Intelligence Group, said the cyber security unit had observed a major increase in so-called LLM-jacking this year, including the sale of stolen login credentials for public AI tools and the theft of computing resources by groups that want to run their own models for free."}],[{"start":37.64,"text":"“What we are seeing in the underground is a growing economy associated with access to AI,” Hultquist, a 20-year cyber security veteran, told the FT."}],[{"start":46.44,"text":"Cheap access to expensive AI gives cyber attackers a financial edge over their targets, who need to use the same AI tools to defend themselves, Hultquist warned."}],[{"start":55.92,"text":"“The bottom line is all this behaviour gives them a sort of economic or efficiency advantage against us, because they’re going to essentially be able to get their hands on these tokens at a much cheaper rate,” he said."}],[{"start":67.44,"text":"Marketplaces on the dark web are selling access to AI models from the likes of Anthropic, Google and OpenAI at discounts of up to 97 per cent, Google Threat’s researchers have found. AI subscriptions for the most advanced versions of ChatGPT and Claude can cost as much as $200 per user every month."}],[{"start":86.28,"text":"Given AI labs monitor for signs of such abuse, some of the sellers even offer “guaranteed access” by committing to provide new credentials at no extra cost if the initial account gets blocked, Hultquist said."}],[{"start":98.2,"text":"In other cases, criminal and state-backed groups are hacking companies’ cloud-hosted servers and dropping in their own AI models to run on the target’s system, in the same way threat actors have sought to compromise third-party machines to mine cryptocurrency. One such incident involved a “very active” Chinese cyber espionage group, which has previously targeted the US, he said."}],[{"start":119.08,"text":"Hultquist has been tracking state-backed hacking groups for two decades. In 2014 he exposed the activities of a prolific Russian actor that he dubbed Sandworm, linking it two years later to an unprecedented attack on Ukraine’s power grid."}],[{"start":132.32,"text":"AI is already being used by “every threat actor”, Hultquist said, adding that AI tools will therefore need to be integral to the future of cyber security. In Anthropic’s most recent quarterly misuse of AI report, it identified threat actors trying to use its Claude tool for malicious activity in more than two dozen countries including the US, UK and Yemen."}],[{"start":153.52,"text":"“Anybody who decides that AI is a fad and wants to let it just wash over them is going to wake up one day underwater,” he said. “They’re going to have more incidents, more alerts, more attacks than they’ve ever seen before. We have to get our house in order now.”"}],[{"start":169.52,"text":"As more large corporations seek to host customised AI models on their own servers instead of renting capacity from cloud providers, those systems will also become a target and will have to be carefully secured, Hultquist warned. “If you’re paying for the compute, which can be very expensive . . . that becomes a major potential resource for a threat actor.”"}],[{"start":189.08,"text":"Hultquist added that the best time for hackers to “sneak in” to targets’ accounts and computer servers was now, given that companies are still learning how much AI they will use. “You might think a sudden major increase in compute usage is completely normal because you have just adopted all this AI infrastructure,” he said. “It’s a real opportunity for somebody to hide in the noise.”"}],[{"start":215.12,"text":""}]],"url":"https://audio.ftcn.net.cn/album/a_1790421015_2622.mp3"}

版权声明:本文版权归FT中文网所有,未经允许任何单位或个人不得转载,复制或以任何其他方式使用本文全部或部分,侵权必究。

黑客劫持AI账户和服务器,助推新一轮网络犯罪热潮

安全研究人员警告称,针对企业昂贵AI资源的“LLM劫持”攻击激增。

随着债券需求减弱,流入美国股市的外国资本创下纪录

截至7月的一年间,海外投资者买入美国股票的金额超过9400亿美元,与标普500指数大幅上涨同期发生。

人工智能数学突破对人类发现意味着什么

解决复杂问题时,过程可能与最终结果同等重要。

旅游税渐成趋势

各国政府看到了一个既能增加财政收入、又不会惹恼选民的办法,也能借此管理蜂拥而至的游客。但休闲旅游业对此并不热衷。

一杯冰咖啡真的会让你丢掉工作吗?

一段提供求职建议的TikTok视频引发了关于面试礼仪的热议。

量子技术能把“魔法”变成金钱吗?

一系列突破和风险投资资金激增,点燃了业内的乐观情绪,但该行业仍面临长期存在的障碍和商业不确定性。
设置字号×
最小
较小
默认
较大
最大
分享×