Look for service enumeration, model listing, unusual billing checks, and rapid follow-on invocation attempts from the same NHI. Those signals indicate that an attacker has moved beyond discovery and is testing whether the credential can be monetised.
How to tell when LLMjacking has moved from reconnaissance to active abuse
The clearest signs are the ones that show the attacker is no longer just probing the surface. Service enumeration, model listing, unusual billing checks, and rapid follow-on invocation attempts from the same NHI all point to someone testing whether the credential can be monetised, not merely discovered.
That pattern matters because llmjacking usually starts with a valid key, token, or gateway credential, then shifts into cheap validation steps that reveal what the credential can reach, what models it can invoke, and whether abuse can be scaled without immediate failure.
A useful way to read those signals is to separate curiosity from exploitation. One-off model discovery can still be benign, but repeated enumeration across services, quotas, regions, or model families is a stronger indicator that the actor is mapping the spend path and looking for the most profitable abuse route.
What the activity pattern usually looks like
Active LLMjacking tends to produce a short sequence of behaviours: first the credential is validated, then the attacker checks inventory and cost exposure, then they begin invoking models quickly or in bursts. LLM Provider API Key Security and LLMjacking Guide is a useful reference point for the access-path side of that sequence, because the core issue is not just secret theft, but what the stolen credential can do once used at runtime.
Watch for repeated requests from a single principal that are low in content diversity but high in operational intent, such as listing available models, checking account or usage endpoints, and then immediately calling generation endpoints. If the same source keeps cycling through those requests, it often means the attacker is confirming that the key is live and that metering, rate limits, or alerting are not stopping them.
The strongest behavioural clue is speed plus repetition. Legitimate automation usually has a stable cadence and a narrow purpose; active abuse often has a bursty, exploratory shape, especially when the actor is trying to find the most permissive model, region, or endpoint before defenders notice.
Why those signals matter operationally
These indicators are valuable because LLMjacking is usually a consumption attack before it becomes a broader compromise. The attacker wants to convert access into spend, output generation, or downstream abuse as quickly as possible, so billing checks and rapid invocations are often earlier than obvious service disruption. That means financial telemetry and API telemetry need to be read together, not separately.
In practice, the moment you see enumeration plus repeated invocation from the same principal, you should treat the credential as live and potentially exposed. Microsoft Azure OpenAI abuse by Storm-2139 illustrates how stolen AI access can be turned into abusive generation at scale, which is why simple presence of a key is less important than the pattern of use around it.
It also helps to think in terms of blast radius. If the credential can see multiple models, projects, or billing scopes, the attacker has more room to test, pivot, and expand spend before failure. The earlier you detect the exploration phase, the more likely you are to contain it before it becomes noisy, expensive, or embedded in other tooling.
How to judge whether the abuse is already underway
The most reliable judgment is whether the behaviour changes from discovery to execution. If the principal moves from listing and checking to repeated successful calls, especially with short intervals between requests, you are likely seeing active abuse. A single failed probe is weak evidence; repeated successful invocations after enumeration are materially stronger.
Use the request pattern, not just the credential name, to make that call. A stolen key that is never used is a containment issue; a stolen key that is enumerating services and generating follow-on traffic is an incident in progress. AI LLM hijack breach is a useful reminder that compromised cloud access can move quickly from initial entry to model abuse and lateral use of the same trust relationship.
If your logs show the same NHI alternating between inventory calls and generation calls, that is usually enough to escalate even before you confirm the business impact. The operational question is not whether the attacker has fully succeeded, but whether the credential is now being exercised in a way that indicates monetisation, persistence, or further abuse.
Risk and Threat Considerations
LLMjacking becomes materially more dangerous once the attacker confirms the credential can enumerate and invoke services. At that point, the same access path can be used to drive cost, exfiltrate model outputs, or probe for broader platform permissions, and the activity can look like ordinary API usage unless you correlate it with timing and sequence.
Failure mechanism: Attackers validate stolen AI credentials, enumerate available services or models, and then rapidly invoke them to test for profitable abuse, rate-limit gaps, or additional access paths.
Impact: Defenders can miss the shift from discovery to exploitation, allowing spend escalation, service abuse, and wider trust compromise before the credential is revoked.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Stolen AI access and exposed keys are central to LLMjacking detection. |
| NHI-05 — Overprivileged NHI | Enumeration and rapid reuse are worse when the credential can reach many models or scopes. | |
| Recommendation — Monitor for leaked API keys and rotate any credential showing suspicious use. Reduce blast radius by limiting each credential to the smallest usable model scope. | ||
| MITRE ATT&CK | T1580 — Cloud Service Dashboard | Attackers often enumerate cloud AI services and account surfaces before abuse. |
| T1078 — Valid Accounts | LLMjacking uses legitimate credentials that are later exercised by an attacker. | |
| Recommendation — Hunt for inventory and account-enumeration activity before active model invocation starts. Treat unexpected successful API use as valid-account compromise and contain it immediately. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Behavioural sequencing across listing and invocation needs correlated log review. |
| IA-5 — Authenticator Management | Suspicious use usually means the credential itself must be rotated or revoked. | |
| AC-6 — Least Privilege | Reducing available models and scopes limits what a stolen credential can monetize. | |
| Recommendation — Correlate API, billing, and identity logs to spot suspicious use patterns early. Rotate or revoke compromised authenticators as soon as active abuse is suspected. Constrain each credential to the minimum model and billing scope needed. | ||
| NIST CSF 2.0 | DE.CM-01 — Monitoring for Unauthorized Personnel, Connections, Devices, and Software | Repeated enumeration and invocation from the same principal are monitorable abuse signals. |
| RS.AN-01 — Analysis | Once abuse is underway, teams need to analyse the sequence and scope of the compromise. | |
| Recommendation — Track anomalous AI API patterns as part of continuous monitoring. Analyse the request sequence to determine whether discovery has become active exploitation. | ||
| OWASP API Security Top 10 | API4 — Unrestricted Resource Consumption | LLMjacking converts valid access into excessive model usage and cost. |
| Recommendation — Rate-limit expensive model endpoints and alert on bursty consumption. | ||
Practitioner Guidance
What to prioritise: Correlate service enumeration, model listing, billing lookups, and invocation bursts by the same principal so you can distinguish reconnaissance from active abuse quickly.
What to verify: Confirm whether the principal is only probing or is already producing successful calls, because successful follow-on invocations are the stronger escalation trigger.
Decision rule: If the same NHI is alternating between discovery and execution, treat the credential as compromised in use and move to containment, rotation, and usage review without waiting for a larger spend signal.
Practitioner takeaway: The key judgment is behavioural sequence, not a single alert, because LLMjacking is underway once the stolen access starts being exercised as a monetisation path.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org