Skip to main content

Underground AI Account Prices More Than Doubled in 2026, Google Finds

Invalid Date|Google|
Secure AI BrainAI Growth Engine

Google Threat Intelligence Group has found that dark web marketplaces are selling stolen access to Claude, Gemini, and Cursor Pro accounts at up to 97% off official pricing. Underground prices for AI credentials more than doubled during 2026. A vendor branded 'Poison Claude' was traced selling Anthropic model access at 5 to 15 percent of per-token rates.

Operator Insight

Enterprises deploying Claude, Gemini, or Cursor Pro are not just managing AI risk internally. Their credentials are now a commodity on underground marketplaces. One stolen API key can fund a threat actor's AI operations indefinitely at your billing rate. The controls that matter are credential rotation schedules, usage-based anomaly detection, and a clear policy on who can provision AI accounts.

30-Second Summary

Google's Threat Intelligence Group has documented a thriving underground market for stolen AI credentials. Accounts for Claude, Gemini, and Cursor Pro are being sold at up to 97% off official pricing, with underground prices more than doubling in 2026 as enterprise AI adoption grew. A vendor branded "Poison Claude" was traced selling Anthropic model access at 5 to 15 percent of official per-token rates. For enterprises, this is not a distant threat. It is a direct financial and compliance risk tied to every provisioned AI account.

At a Glance

  • Topic: AI Security
  • Company: Google (reporting), Anthropic and others (affected)
  • Date: September 2026
  • Announcement: Google Threat Intelligence Group published findings on underground AI credential marketplaces
  • What Changed: Underground prices for stolen AI accounts more than doubled in 2026, tracking the growth of enterprise AI deployment
  • Why It Matters: AI credentials are now a valued commodity on dark web marketplaces, creating a direct financial and data security risk for any organisation using AI APIs
  • Who Should Care: Any business with AI API keys, enterprise AI subscriptions, or staff using AI coding tools

Key Facts

  • Underground AI account prices more than doubled during 2026, according to Google Threat Intelligence Group as reported by the Financial Times (September 2026)
  • Stolen Claude, Gemini, and Cursor Pro accounts are being sold at up to 97% below official pricing on dark web marketplaces (Google Threat Intelligence Group, September 2026)
  • Okta traced a vendor branded "Poison Claude" selling access to Anthropic's Opus 4.6 to 4.8 and Sonnet 4.6 at 5 to 15 percent of official per-token pricing (Okta research, September 2026)
  • Buyers on underground markets are concentrating specifically on Claude and Gemini credentials, plus autonomous coding tools including Cursor Pro and Devin (Google Threat Intelligence Group, September 2026)

What Happened

Google Threat Intelligence Group has documented a substantial underground market for stolen AI credentials, with findings reported by the Financial Times in September 2026. The average price for stolen access to major AI platforms more than doubled during 2026, with marketplaces offering access to Claude, Gemini, and Cursor Pro at up to 97% below the official per-token or subscription rate.

The growth in underground AI credential pricing tracks directly with enterprise AI adoption. As more organisations have integrated AI into production workflows, the value of compromised credentials has increased. A single stolen API key can give a threat actor access to a frontier AI model at the account holder's billing rate, at no direct cost to the attacker.

Okta's research identified a specific vendor operating under the brand "Poison Claude" found selling access to Anthropic's Opus 4.6, Opus 4.8, and Sonnet 4.6 at 5 to 15 percent of official per-token pricing. The vendor was offering access via stolen or compromised API keys, effectively reselling enterprise AI capacity to anyone willing to pay.

Google Threat Intelligence Group noted that buyers in underground markets are specifically concentrating on Claude and Gemini credentials, plus autonomous coding IDEs such as Cursor Pro and Devin. This suggests threat actors have assessed these tools as the most valuable for downstream use: AI-assisted coding, content generation at scale, and agentic task execution.

Why It Matters

The risk is financial, not just reputational. A stolen API key is a direct billing liability. Threat actors using your credentials generate charges against your account. Organisations without spend-based alerts may not discover the breach until they receive an unexpectedly large invoice. The financial exposure scales with usage, not with the original value of the stolen credentials.

Compliance implications are real and growing. Australian Privacy Principles and the Notifiable Data Breaches scheme require notification when personal information may have been accessed. If a stolen API key was used to process any data that included personal information, the organisation holding that key may have notification obligations, even if they were the victim rather than the attacker.

The underground market is segment-specific. The concentration on Claude, Gemini, and Cursor Pro tells operators something useful. These are the platforms threat actors consider most capable and most in-demand. If your organisation is among the early adopters of these tools, your credentials are precisely what underground buyers are looking for.

Credential hygiene for AI is lagging behind cloud. Most enterprises have mature practices for managing cloud provider credentials: key rotation, access scope limitations, usage anomaly detection. AI API key management typically lags. Many organisations have issued keys to individual developers or team members without the governance controls applied to other infrastructure credentials.

The attack surface grows with every new deployment. Every new AI integration, every new team member granted API access, and every new AI subscription creates another potential credential for the underground market. Unlike a single data breach, this is an ongoing and expanding risk that scales with AI adoption.

The David and Goliath View

This finding from Google is worth treating as a category-defining signal rather than a one-off security story. Underground markets do not scale unless there is sustained demand. The doubling of AI credential prices in 2026 reflects two things: the growing capability of AI tools and the growing number of enterprises that have deployed them without mature credential governance.

The vendors selling "Poison Claude" are not running sophisticated operations. They are exploiting a governance gap that most organisations created when they moved quickly on AI adoption and skipped the credential management discipline they would apply to any other infrastructure access key. The fix is not complex, but it requires treating AI API keys as a genuine security asset, not a developer convenience.

For a 50-person professional services firm using Claude for research, drafting, and analysis, the exposure from a single compromised key is potentially months of enterprise AI usage costs plus the compliance obligation that comes with any data that passed through that session. That is not hypothetical. It is the risk profile of the underground market Google has documented.

Where This Fits in the AI Stack

This story sits at the intersection of AI infrastructure and enterprise security governance. The credential theft problem is not specific to any one AI vendor. It applies to any organisation that has provisioned API access to frontier models. Anthropic, Google, and OpenAI all have controls on their platforms, but those controls rely on the API key holder reporting compromise, not on detecting underground resale.

The defensive position is governed access: centralised credential management, usage-based anomaly alerts, and a key rotation policy that treats AI credentials with the same seriousness as cloud IAM. Organisations already running mature cloud security operations have the muscle memory to apply this. Those who rushed AI deployment without security review are the most exposed.

Questions Operators Are Asking

How would I know if my AI credentials had been compromised? The most reliable signal is unusual API usage, specifically calls at unexpected times, from unexpected IP ranges, or consuming tokens at a rate inconsistent with your team's work patterns. Spend-based alerts on every API key, set to notify at 150% of expected monthly usage, will catch most cases before they become expensive. Check your AI provider's usage dashboard and confirm billing alerts are configured.

Is this just a risk for large enterprises? No. Underground buyers purchase access to AI tools for their own productivity, not primarily for data theft. A small business with a single Claude API key is as exposed as a large enterprise in terms of the credential itself. The financial exposure is smaller in absolute terms but proportionally significant.

Should I move to OAuth or SSO-based AI access instead of API keys? Where your AI vendor offers it, yes. SSO-based access ties authentication to identity provider controls, supports conditional access policies, and gives you a deprovisioning path when a team member leaves. API keys are persistent by default and must be actively rotated. The fewer raw API keys in circulation in your organisation, the better.

What should I do right now? Audit every active AI API key in your organisation. For each one, confirm who holds it, when it was last rotated, whether usage alerts are configured, and what data it has access to. Then set a rotation schedule and enforce it. This takes a few hours and reduces a tangible ongoing risk.

Are Anthropic and Google doing anything about this? Both companies have usage monitoring and anomaly detection on their platforms. Google's Threat Intelligence Group publishing these findings publicly is itself a defensive act: it names the threat and gives operators the context to act. Platform controls are a backstop, not a substitute for credential governance by the organisations using these tools.

Citable Summary

Google Threat Intelligence Group documented a growing underground market for stolen AI credentials in September 2026. Prices for stolen Claude, Gemini, and Cursor Pro accounts more than doubled during 2026, with marketplaces offering access at up to 97% below official pricing (Google Threat Intelligence Group, Financial Times, September 2026). A vendor identified as "Poison Claude" was found reselling Anthropic model access at 5 to 15 percent of per-token rates (Okta research, September 2026). Buyers are concentrating on Claude and Gemini credentials and autonomous coding tools. The finding highlights a credential governance gap: enterprises deploying AI at scale often lack the key rotation, usage alerting, and access scoping controls applied to other infrastructure credentials.

Why This Matters for Operators

  • ✓

    Audit who holds API keys for Claude, Gemini, and Cursor Pro in your organisation. Every provisioned account is a potential credential for sale.

  • ✓

    Set spend-based alerts on every AI API key. Unusual usage is often the first and only signal of credential theft.

  • ✓

    Rotate API keys on a fixed schedule, quarterly at minimum, and immediately on any team member departure.

  • ✓

    Treat AI credentials with the same policy discipline as cloud access keys. Underground pricing suggests they are valued comparably.

  • ✓

    Consider centralising AI access through a gateway or proxy that normalises usage and simplifies audit, rather than distributing raw API keys to individuals.

Related Intelligence

Related Signals

  • [High] Google Gemini 3.1 Pro leads 13 of 16 benchmarks at one-third of GPT-5.4 cost

    Gemini 3.1 Pro leads 13 of 16 major benchmarks on the Artificial Analysis Intelligence Index and ties GPT-5.4 Pro on the overall index, at roughly one-third of the API price. The result puts direct pressure on OpenAI enterprise pricing across cost-conscious buyer segments.

Related Comparisons

How This Maps to David & Goliath

Apply This to Your Business

Want to see what this means for your team?

Tell us a little about your business and we will map the specific opportunity for your sector and team size.

No sales pitch. We will review your details and follow up within 24 hours.