Cybersecurity Research

‘Token Jacking’: How Hackers Are Stealing AI Resources From Businesses

Unit 42 · 6 Aug 2026
Key Takeaway Treat API keys and AI service credentials with the same care as passwords: store them securely, rotate them regularly, and never expose them in code or shared files.

A new cyberattack trend dubbed 'token jacking' is putting businesses that use AI tools and services at risk. According to research from Unit 42, attackers are stealing developer API keys — the digital credentials that let software access AI platforms — and using them to hijack AI tokens, which represent paid usage or credits on these services.

Once stolen, these tokens are funnelled through so-called gray market 'transfer stations', where criminals resell access to AI resources that rightfully belong to compromised businesses. This means a company could unknowingly be paying for AI usage that is actually being consumed by criminals, while also facing potential data exposure and reputational damage if their API keys are misused.

As more Australian small businesses adopt AI tools for productivity, customer service, and automation, protecting the API keys and credentials that connect to these services is becoming just as important as protecting passwords or financial data. Poorly secured keys — such as those left in code repositories, shared documents, or unsecured configuration files — are prime targets for this kind of theft.

AI security API keys token jacking cybercrime SMB security
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Unit 42. We link back to every original so you can read it yourself.