Resource jacking is the unauthorized use of an organisation’s cloud, API, or compute resources by an attacker. The attacker typically abuses exposed credentials to run workloads, consume paid services, or mine cryptocurrency, creating cost, performance, and security impact for the victim.
Expanded Definition
Resource jacking is the unauthorised consumption of cloud, API, or compute capacity for an attacker’s benefit. It is usually enabled by stolen or exposed credentials, but the core issue is not theft of data; it is misuse of someone else’s authorised environment to run workloads, exhaust quotas, or generate cost.
The term covers several closely related abuses: cryptocurrency mining, proxying workloads through another tenant, abusing serverless functions, or running automation that burns CPU, memory, bandwidth, or API calls. It excludes ordinary overuse by legitimate users and simple outages caused by noisy neighbours, although the operational symptoms can look similar. In practice, resource jacking is often discovered through billing anomalies, sudden performance degradation, or unexpected scaling behaviour rather than a direct security alert.
Definitions vary slightly across vendors because some describe the issue as cloud abuse, while others treat it as a credential-driven billing fraud pattern. The security substance is the same: an attacker converts trusted access into measurable resource consumption.
Examples and Use Cases
Resource jacking appears wherever access to metered infrastructure can be turned into sustained consumption. It is most visible in cloud accounts, but the pattern also shows up in exposed CI/CD runners, API gateways, and managed compute platforms.
- A stolen access key is used to launch instances that mine cryptocurrency until the bill or quota limit reveals the abuse.
- An exposed API token is used to drive high-volume requests against a paid service, exhausting rate limits and increasing spend.
- A compromised workload identity is used to start ephemeral jobs that blend into ordinary automation while consuming CPU and storage.
- Attackers repurpose serverless functions or container platforms to run transient workloads that are harder to notice than long-lived hosts.
- In some environments, the same access path supports both resource theft and broader intrusion, which makes the abuse harder to separate from normal administration.
One practical tradeoff is that aggressive cost controls can catch abuse earlier, but they can also interrupt legitimate bursty workloads if ownership and baselines are unclear.
Security Implications
Resource jacking creates direct financial loss and can also become an operational incident. When an attacker consumes compute, storage, bandwidth, or third-party API capacity, the victim may see degraded performance, service throttling, failed deployments, or unexpected shutdowns when budgets and quotas are reached.
Because the abuse often begins with valid credentials, it can stay hidden longer than malware that triggers endpoint controls. That means the first visible symptom may be a cost spike, not a security alert. NHIMG research notes that 97% of NHIs carry excessive privileges, which broadens the blast radius when a single credential is abused for metered-resource consumption.
Failure mechanism: exposed or overprivileged credentials are reused to authenticate normal-looking jobs, functions, or API calls, letting the attacker spend someone else’s capacity under legitimate access paths.
Impact: organisations absorb unnecessary cloud spend, lose capacity for real workloads, and may also face secondary exposure if the abused identity has permissions beyond the initial resource-jacking activity.
Domain and Governance Relevance
Resource jacking matters most in cloud and identity governance because the abuse is usually enabled by weak control over machine credentials, service accounts, or automation tokens. The term is therefore not just about cost control; it is also about who can consume what, on whose behalf, and under what monitoring.
For NHI governance, the important shift is that identity scope and lifecycle become financial controls as well as security controls. If a workload identity can create compute, call billable APIs, or spin up ephemeral jobs without strong ownership and revocation discipline, then the organisation has created an easy path from credential exposure to direct monetary loss.
That is why visibility into machine identities, their privileges, and their usage patterns is central to preventing this abuse. A well-governed environment reduces the chance that a single leaked token becomes an open-ended spending instrument.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secrets and Credential Management | Resource jacking commonly starts with exposed machine credentials used to spend resources. |
| NHI-04 — Privilege and Authorization Boundaries | Overprivileged NHIs let attackers expand from access to broad resource consumption. | |
| Recommendation — Rotate and revoke exposed non-human credentials before they can be used for billable workload abuse. Constrain workload permissions so a stolen identity cannot launch or scale resources freely. | ||
| CIS Controls v8 | 6 — Access Control Management | Resource jacking depends on abuse of valid access paths that should be tightly governed. |
| 4 — Secure Configuration of Enterprise Assets and Software | Misconfigurations often expose automation paths that enable unauthorised resource consumption. | |
| Recommendation — Remove stale access, enforce least privilege, and review who can invoke paid cloud services. Harden cloud and CI/CD defaults to prevent exposed keys, permissive execution, and runaway scaling. | ||
| NIST CSF 2.0 | PR.AC-1 — Identities and Credentials Issued, Managed, Verified, Revoked | The abuse relies on credentials that remain valid long enough to be misused. |
| Recommendation — Manage credential lifecycle tightly so compromised access cannot keep generating spend. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org