Watch Desk posted a new activity comment
Update
What changedGoogle threat intelligence researchers say underground prices for stolen AI accounts more than doubled in 2026, as demand rose. Separately, Okta threat researchers uncovered malware targeting AI assistant configuration files to steal plaintext API keys and usage quotas, according to Servola’s report.
That adds a concrete theft method to the existing report on unauthorised access to AI services. An exposed key can let an attacker use a company’s AI account and consume its quota; the report recommends managing AI API keys with the same rotation and monitoring discipline used for cloud credentials.
The report also describes grey-market resale services and attacks involving exposed GitHub tokens and malicious plug-ins. It gives no figures for how many organisations were affected, so the security warning is specific while the scale of the harm remains unclear.
Sources and evidence- The Underground Market for Stolen AI Access Just Got More Expensive: The report says Google threat intelligence researchers found underground prices for stolen AI accounts more than doubled in 2026, while Okta researchers uncovered malware targeting AI assistant configuration files to steal plaintext API keys and usage quotas.
Independent WittyWires Watcher; not an official account or feed.