Hacked access keys: when your AI services bill explodes in 48 hours

On a Monday morning, a billing alert. An SME dashboard shows tens of thousands of francs in usage in forty-eight hours, on…

On a Monday morning, a billing alert. An SME dashboard shows tens of thousands of francs in usage in forty-eight hours, on artificial intelligence services that no one in the company has ever enabled. In a recent case, the bill exceeded several hundred thousand francs before the mechanism was understood. The scheme, referred to across the Atlantic by the anglicism LLMjacking, consists of hijacking a company’s access keys to consume, at its expense, artificial intelligence services resold to third parties. It targets precisely the companies that think they are not a target.

The mechanism, in plain terms

It all starts with a compromised access key. A technical identifier, a string of characters that allows your applications to consume remote IT services, and that is left where it should not be: a public code repository, an infected developer workstation, an external provider’s machine. Fraudsters no longer even need to look for them themselves; bots constantly scan public repositories and spot an exposed key within minutes.

What the fraudster steals next is not your data. It is your billing capacity. With the key, they activate the most expensive AI models on the market, then resell access to hundreds of anonymous users via relay servers. Each request, each line of generated text, is billed to your account. The scheme has been documented by security researchers since 2024; observed amounts reach tens of thousands of dollars per day on a single compromised account.

The brutality of the scheme comes down to a simple asymmetry: the provider bills by usage, with no default cap. As long as the key works, the meter keeps running.

Why your SME is exposed

Three weaknesses recur in almost every case. Access keys with overly broad permissions, created for a test and never revoked. Billing with no maximum budget and no aggressive alerts, because historical usage was modest and no one imagined a hundredfold increase. And the absence of any monitoring of call logs, the only way to see that at three in the morning, your account is generating text continuously for unknown users.

In truth, none of these gaps is exotic. It is the everyday reality of a company that digitized quickly and effectively, without a dedicated security team. Precisely the profile of Swiss SMEs.

The first 48 hours

The reflex that matters: immediately revoke all access keys on the account, not just the one that appears compromised. Fraudsters often create new ones as soon as they have access. Immediately after, disable AI services at the organization level, set spending caps and billing alerts, and change administrator access.

Next, preserve the evidence. Access and consumption logs are your case file: they establish the geographic origin of requests, their volume, and how clearly unrelated they are to your business. Export them without delay; some providers keep them only for a few weeks.

Third front: the bill. Dispute it in writing, immediately, without waiting for the debit. A letter that sets out the compromise, quantifies the fraudulent usage, and reserves all rights is nothing like a resigned support request. Above all, do not pay “in the meantime”: payment is quickly interpreted as an acknowledgment.

What the terms and conditions say

The terms and conditions of major providers are unambiguous on one point: safeguarding credentials is the customer’s responsibility, and any activity carried out using its keys is deemed to be its own. Added to this are liability caps indexed to amounts paid, exclusions for indirect damages, and, frequently, a choice of law and foreign forum. Prima facie, the ground is unfavorable.

Yet you must read those same terms to the end. They almost always contain a deadline for disputing invoices, often thirty days from issuance: letting it lapse amounts to validating the bill. They impose a claims procedure that must be followed formally, failing which the provider will raise a procedural defect before any debate on the merits. Finally, they reserve mechanisms for credits or adjustments for abnormal usage, applied at the provider’s discretion. Discretionary means negotiable.

That leaves the substantive argument. A hundredfold increase in usage in two days, from jurisdictions unrelated to the customer, on services never previously enabled: the provider, which deploys for its own needs some of the most sophisticated anomaly-detection systems on the market, can hardly maintain that it could not see anything. Billing without blinking for the consequences of detectable fraud raises questions about good faith in the performance of the contract. The argument does not win on its own; it structures the negotiation. In the case mentioned above, a detailed dispute, supported by logs and built around the provider’s own clauses, opened a discussion that three support requests had never achieved.

In plain terms: the terms and conditions set the starting point of the balance of power, not its end point.

A criminal complaint formalizes the case

Filing a complaint is not a gesture of irritation. It is an act of structuring. The complaint fixes the facts as of a certain date: the compromise, its discovery, the measures taken, the quantified loss. It legally establishes the company’s status as the victim of offences (unauthorized access to a computer system, art. 143bis SCC; fraudulent use of a computer, art. 147 SCC), and not as a distracted debtor of an IT services invoice. The nuance changes everything, both with the provider and with the insurer.

It also opens levers that civil proceedings do not offer: seizure, tracing of the infrastructures used, international mutual assistance. The fact that the perpetrators operate from abroad changes nothing; Swiss authorities have jurisdiction as soon as the damage occurs here. Even without rapid identification of the perpetrators, the procedure documents the company’s diligence. A cornerstone of the file, on all fronts at once.

The board of directors must protect itself

A six-figure incident is no longer an IT issue. It is a governance issue. Art. 716a CO places the organization and overall supervision of management among the non-transferable duties of the board of directors; keys exposed for months, the absence of any billing cap, and a basic security failure can support a liability action (art. 754 CO), brought as the case may be by a shareholder or, in the event of bankruptcy, by the bankruptcy estate.

The response comes down to two documents. A board resolution noting the incident, mandating the legal steps, and approving the remediation plan. And an independent security report establishing the cause of the compromise, the corrective measures, and their effective implementation. This resolution-report pair protects directors, strengthens the company’s position with the insurer, and shows the provider that it is dealing with an organization that takes the incident seriously, not a customer trying to wipe a slate clean. In other words: documented governance is also a negotiation argument.

What changes with a lawyer who knows the subject

These cases are often lost before they are even argued, on three distinct fronts.

First, the complaint. A generic complaint that speaks of “hacking” without describing the mechanism is dismissed for lack of an actionable lead. A precise complaint, which correctly characterizes the offences, reconstructs the chain of compromise, attaches sorted and readable logs, and identifies the infrastructures used, gives the public prosecutor something to work with. The prosecutor must understand the scheme in ten minutes of reading. It is drafting work, not a form.

Next, the provider. Facing a giant that receives thousands of claims, tone decides a great deal. Grievances end up in a queue; empty threats shut down the discussion. What works is a cooperative but firm letter, grounded in the provider’s own clauses, precisely quantifying the fraudulent usage and placing the institution before a measurable procedural and reputational risk. Experience shows that the same file, presented differently, changes desk: it leaves customer support and reaches the legal department. That is where negotiation happens.

Then there is the technical side. A lawyer who confuses an access key with a password wastes everyone’s time—and the file’s credibility. Reading the logs, distinguishing legitimate usage from fraudulent usage, speaking on equal terms with your teams and the expert appointed for the security report: this understanding of the mechanism is not a luxury; it determines the quality of the complaint as well as the negotiation.

Frequently asked questions

What is LLMjacking?

The hijacking of a company’s access keys to consume, at its expense, artificial intelligence services that are then resold to third parties. The victim does not lose its data; it receives the bill for massive usage it never ordered.

Does the provider have to cancel the bill?

Not automatically. But substantial discounts, sometimes total, can be obtained when the dispute follows the procedure and deadlines in the terms and conditions, relies on the logs, and demonstrates detectable anomalies. The quality of the file makes the difference.

Does my insurance cover this type of loss?

Depending on the policy, fraud involving billed services does not always fall within the classic definitions of loss linked to cybercrime. Report the claim immediately, provide the complaint and the security report, and have the clauses reviewed before accepting a refusal.

Do I really need to file a complaint if the perpetrators cannot be found?

Yes. Even without rapid identification of the perpetrators, the procedure freezes the evidence, strengthens your position with the provider and the insurer, and may be joined to ongoing international investigations into the same infrastructures.

About the author

Matthias Traussnig is a lawyer admitted to the Geneva Bar and the founder of Sentinel Legal. He holds a CAS in Digital Finance Law from the University of Geneva, where he also teaches on fraud related to digital assets, and he practices in economic crime, criminal law, and technology law.

On these types of cases

These matters play out on three fronts at once: evidence and securing in the first hours, the contractual showdown with the provider, and the criminal and governance structuring. Sentinel Legal acts in economic crime and technology law, from disputing the bill to filing a criminal complaint and advising the board of directors. To discuss a situation: +41 22 512 76 00 or via the contact form.

Partager cet article LinkedIn

Votre situation mérite une lecture lucide.

Notre équipe est disponible pour analyser votre dossier en toute confidentialité.