top of page

The First Sign You Have Been Hacked May Be An Invoice

Attackers are stealing corporate AI credentials and running up the victim's inference bill, which means finance may notice the breach before security does.



Sign up for my Substack daily AI newsletter here.


See my AI Training course portfolio for corporate Business Leaders here.




Most intrusions announce themselves through the security function, if they announce themselves at all. A new attack pattern discussed at a recent Black Hat conference reverses that. The organisation’s first indication that something is wrong may arrive from the finance department, in the form of a bill nobody can explain.


CONTEXT AND BACKGROUND

Protecting internal AI systems was among the dominant themes at Black Hat in Las Vegas, where more than 20,000 people gathered. Criminals are increasingly buying and reselling ChatGPT, Claude and Gemini credentials stolen from legitimate accounts, a practice that has run since late 2022. In one documented campaign, a group sent nearly 200,000 requests in two minutes using access to a corporate AI account. Attackers avoid paying for their own tokens, passing the cost to the organisations they compromise, and the activity is difficult to spot because software agents are expected to operate at odd hours in the first place.


The technique now has a name. Alongside the theft of credentials to reach frontier model interfaces, researchers describe it as cost harvesting, being the deliberate inflation of a victim’s AI usage to drive up its bill, with AI described as both the weapon and the target.


INSIGHT AND ANALYSIS

Two things make this different from ordinary account compromise. The first is that the attacker’s operating cost lands on the victim’s account, which removes the economic constraint that usually limits how much an intruder can do before being noticed. The second is that the resulting activity looks like enthusiasm. Requests at three in the morning, in high volume, on unfamiliar topics, describe both an intrusion and a diligent deployment, so the behavioural baseline that detection depends on has been erased by the technology itself.


The consequence is organisational rather than technical. An unexplained increase in AI spend now carries two possible explanations, being that a team has scaled up its usage, or that somebody else is using your account. In most organisations, the person who sees that number first sits in finance, reports through a different executive, and has no reason to treat it as anything other than a budgeting question. AI cost monitoring and AI security monitoring have become the same function while remaining in separate hands.


IMPLICATIONS

South African organisations carry this exposure in a harder currency. Local enterprises using hyperscalers already face fluctuating operational costs because of rand volatility against the dollar, and many have experienced cloud bill shock, with the local cloud services market projected to grow from an estimated R49.6 billion in 2025 to R101.5 billion in 2029.


An inflated inference bill therefore arrives with a currency penalty attached to the intrusion. The regional context is unfavourable too. INTERPOL reports that AI now enables 55 percent of reported cybercrimes across Africa, and that losses have more than doubled since 2024, from 192 million to 484 million dollars, driven primarily by AI-facilitated scams, credential harvesting and automated social engineering. South Africa is identified as particularly exposed because of its advanced digital economy, with financial institutions and telecommunications operators facing AI-driven credential harvesting, phishing and synthetic identity fraud. Credential harvesting is not an emerging concern here. It is a documented and growing loss pattern.


CLOSING TAKEAWAY

Three questions follow, and none require new expenditure. Does anybody currently review AI spend against expected usage, and how quickly would a doubling be noticed? Does the person who sees that number know it is a security signal rather than a procurement matter? Is there a single agreed figure for what the organisation should be spending, since a variance cannot be detected without a baseline? The uncomfortable answer in most organisations is that the finance team would notice first and would say nothing, because nobody has told them the number means something. That is a conversation between two executives, and it costs an afternoon.


Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net


 
 
 

Comments


Leveraging AI in Human Resources ​for Organisational Success
CTU Training Solutions webinar

bottom of page