September 27, 2026
Your AI Accounts Are Now a Target: What the Latest Threat Research Means for UK Firms
By GLCTech Sec | September 2026 | glctechsec.com

By GLCTech Sec
4 min read
For years, the cybersecurity conversation for most businesses has been about data: stop it being stolen, stop it being encrypted, and be able to restore it if the worst happens. That is still true. But research published this month by Google, Okta and Anthropic shows attackers adding a new target to the list: the AI tools, API keys and cloud accounts businesses now rely on every day.
At GLCTech Sec, we work with accountancy, legal and financial services firms across the UK. Many of them have adopted AI assistants, AI-enabled software and cloud AI services over the past two years. This article summarises what the new research actually says, without the hype, and what a practical response looks like for a regulated SME.
What the research found
1. Attackers are stealing AI access, not just data. Google Threat Intelligence Group's AI Threat Tracker (8 September 2026) reports adversaries targeting proprietary AI models and source code, stealing API credentials, and taking over victims' cloud environments to run unauthorised AI workloads. Google describes enterprise AI assets, from model weights to cloud compute quotas, as high-value targets for espionage, extortion and resource theft.
2. Stolen AI access has become a traded commodity. According to Financial Times coverage of Google's findings, underground prices for stolen AI accounts, particularly Claude and Gemini accounts, more than doubled during 2026. No per-account prices have been published, but the direction is clear: there is a market, and demand is rising.
3. The bills land on the victim. The industry term for this is "LLMjacking", coined by Sysdig's threat research team in 2024. Attackers use stolen cloud or API credentials to run AI workloads and leave the account owner to pay. Sysdig estimated at the time that one such attack could generate more than US$46,000 of AI usage costs per day. Okta Threat Intelligence's September 2026 research describes cases including a bill of nearly US$1 million for one organisation and a US$25,000 surprise bill for an individual software architect.
4. Stolen login sessions bypass passwords and MFA. Okta's research analysed infostealer malware logs, which hold data harvested from infected computers, and found large numbers of AI-platform session tokens. A session token is what keeps you logged in. If one is stolen from an infected laptop, an attacker can replay it and step straight into the account without knowing the password or passing multi-factor authentication.
5. Exposed keys are found fast and exploited faster. Anthropic's September 2026 threat report describes attackers systematically searching public code repositories, container images, apps and websites for credentials and API keys. In one case it documents, a single stolen developer token escalated to full administrative control of a victim's cloud environment in roughly three hours.
6. AI data is being used for extortion. Google's Mandiant investigated several data-theft extortion cases in Q2 2026. Attackers stole proprietary AI models, prompts, source code and research from technology, healthcare and media companies in North America and Europe, then threatened to publish the data unless a ransom was paid.
7. Regulators are starting to see AI-executed breaches. On 14 September 2026, Spain's data protection authority (AEPD) reported receiving its first breach notification in which the affected organisation said an AI agent, built on a well-known language model, logged in and autonomously found a flaw that let it modify personal data and access invoices. The AEPD stressed that the account comes from the victim's notification and is still being analysed. It is a useful reminder that breach-notification duties apply no matter what kind of attacker was involved. Under UK GDPR, notifiable breaches must be reported to the ICO within 72 hours.
Why this matters for accountancy, legal and financial firms
Most UK professional-services SMEs are not training their own AI models, so model theft is not the main risk for them. The realistic exposure is more ordinary, and therefore more likely:
- An infected laptop leaks the browser session for your firm's AI assistant, email or cloud accounts.
- An API key for an AI-enabled tool gets pasted into a script, shared file or code repository.
- An unexpected spike in cloud or AI usage goes unnoticed until the invoice arrives.
- Client data processed through AI tools becomes part of what an attacker can reach.
In other words, AI has not replaced the basics. It has raised the cost of getting them wrong.
A practical response
The organisations behind this research all point to the same fundamentals:
- Protect the endpoint. Infostealers run on user devices. Managed, monitored endpoint protection is the first line of defence against session-token theft.
- Keep secrets out of code and shared files. Scan repositories and containers for exposed keys, store credentials in a secrets manager, and rotate anything that has been exposed.
- Watch for the anomaly. Set spending limits and billing alerts on cloud and AI services, and monitor infrastructure for unusual activity so a hijacked key shows up in hours, not at month-end.
- Assume extortion and plan recovery. Immutable, tested backups mean a ransom demand is a problem to manage, not a crisis.
- Treat AI assets as sensitive. Prompts, AI configurations and the data you feed into AI tools deserve the same access controls as client files.
The UK's National Cyber Security Centre guidance for small and medium-sized organisations is a good free starting point.
How GLCTech Sec helps
GLCTech Sec provides three services that map directly onto these risks:
- Managed Endpoint Security, vendor-agnostic (Kaspersky, Microsoft Defender for Business, Bitdefender or Sophos), to reduce the infostealer infections that leak session tokens.
- 24/7 Zabbix Infrastructure Monitoring, with Grafana dashboards and email and WhatsApp alerts, so unusual activity across servers, networks and applications is spotted early.
- Veeam Backup & Recovery, so you can recover without paying if extortion hits.
We also publish our own security posture openly on our Trust & Compliance page, including UK GDPR processing terms and our progress towards Cyber Essentials, because we expect our clients to be asked hard questions in procurement too.
Not sure where your firm stands? Book a free 30-minute Security Gap Assessment at glctechsec.com, or email contact@glctechsec.com.
Sources
- Google Threat Intelligence Group, GTIG AI Threat Tracker: From Prompting to Autonomy — The Evolution of Adversarial AI, 8 September 2026. https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
- Okta Threat Intelligence (Jeremy Kirk), Signing in without actually signing in, 9 September 2026. https://www.okta.com/blog/threat-intelligence/signing_in_without_actually_signing_in/
- Anthropic, Detecting and countering misuse of AI: September 2026, 10 September 2026. https://www.anthropic.com/threat-intelligence-report-september-2026
- Sysdig Threat Research Team, LLMjacking: Stolen Cloud Credentials Used in New AI Attack, 6 May 2024. https://www.sysdig.com/blog/llmjacking-stolen-cloud-credentials-used-in-new-ai-attack
- Agencia Española de Protección de Datos (AEPD) blog, 14 September 2026 (Spanish). https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia
- AI Weekly, Google: underground AI account prices more than doubled in 2026 (reporting FT coverage of GTIG). https://aiweekly.co/alerts/google-underground-ai-account-prices-more-than-doubled-in-2026
- NCSC, Cyber security advice for small to medium sized organisations. https://www.ncsc.gov.uk/section/advice-guidance/small-medium-sized-organisations
- ICO, Report a breach. https://ico.org.uk/for-organisations/report-a-breach/