
➤Summary
Artificial intelligence has become a critical business tool, but cybercriminals are finding new ways to exploit the growing demand. A recently uncovered operation shows attackers abusing cloud startup credit programs to obtain free access to premium AI services, including Claude and Gemini, before reselling that access through underground marketplaces. The campaign demonstrates how legitimate cloud incentives can be manipulated to create profitable criminal services while making attribution more difficult. This development highlights why cyber threat monitoring has become increasingly important for organizations relying on cloud infrastructure and AI technologies. 🤖🔐
According to security researchers, threat actors are registering fraudulent startup accounts, collecting promotional cloud credits, and using those resources to operate premium AI models at little or no cost. Instead of using the credits for innovation, they monetize them by selling AI access to other cybercriminals, enabling phishing campaigns, malware development, fraud, and other malicious activities. The discovery raises broader concerns about cloud identity abuse, verification weaknesses, and the growing commercialization of AI within cybercrime ecosystems.
Researchers recently identified a scheme in which cybercriminals exploit startup incentive programs offered by major cloud providers. These programs are designed to help legitimate startups build products by providing free infrastructure credits during their early growth stages.
Rather than launching genuine businesses, attackers create fraudulent startup identities or abuse compromised accounts to qualify for these benefits. Once approved, they use the allocated cloud credits to deploy premium AI services such as Claude and Gemini without paying standard subscription fees.
Instead of consuming the AI services themselves, criminals advertise access across underground forums, encrypted messaging platforms, and illicit marketplaces. Buyers receive API keys or shared accounts that allow them to leverage advanced AI models for a wide range of malicious purposes.
The operation effectively transforms free promotional cloud credits into an underground revenue stream while significantly lowering operational costs for cybercriminal organizations.
Researchers also noted that cloud providers continuously improve fraud detection, but the scale of automated identity creation and synthetic startup applications creates ongoing challenges. These campaigns illustrate how legitimate business incentive programs can unintentionally become resources for criminal enterprises. The findings were originally reported by GBHackers.
Unlike traditional breaches, this incident does not center on a database leak containing customer information. Instead, it involves abuse of cloud resources and AI infrastructure.
However, the broader implications are significant because attackers may leverage:
Once attackers obtain AI access, they can dramatically improve the scale and sophistication of cyber operations.
For example, AI can assist with:
Organizations performing continuous stolen credentials monitoring are more likely to detect compromised cloud identities before they are abused for these types of operations.
The campaign highlights a growing trend in cybercrime: attackers increasingly abuse legitimate cloud services instead of building their own infrastructure.
This provides several advantages.
Premium AI services normally require expensive subscriptions or API usage fees. By exploiting startup credits, criminals essentially receive enterprise-grade AI capabilities for free.
Cloud platforms provide trusted infrastructure that blends malicious activity with legitimate customer traffic, making investigations more challenging.
Large language models significantly reduce the time required to:
Threat actors can launch campaigns much faster than before.
AI lowers technical barriers. Individuals with limited programming knowledge can use AI-generated scripts or attack guidance to conduct increasingly sophisticated operations.
This democratization of offensive capabilities expands the overall cybercrime ecosystem.
The impact extends well beyond cloud providers.
Organizations potentially affected include:
Startups using cloud incentive programs may experience increased scrutiny during verification processes as providers strengthen anti-fraud controls.
Businesses relying on AI-powered applications may become indirect targets as attackers imitate legitimate AI usage or abuse compromised API credentials.
Banks and payment processors may encounter increasingly convincing AI-assisted fraud campaigns.
Medical providers remain attractive phishing targets, and AI-generated communications can improve attack success rates.
Public-sector organizations frequently face sophisticated spear-phishing campaigns that may now leverage advanced AI-generated content.
SMBs often lack dedicated security teams, making them attractive victims for AI-enhanced phishing and business email compromise attacks.
Organizations without continuous cyber threat detection capabilities may struggle to recognize early warning indicators before attackers establish persistence.
The abuse of startup credits represents a broader evolution in cybercrime.
Instead of stealing infrastructure, attackers increasingly exploit legitimate business incentives.
This mirrors previous trends involving:
As AI services become more valuable, incentive abuse will likely expand across additional providers.
Future campaigns may involve:
These developments emphasize the importance of continuous cyber threat monitoring rather than relying solely on traditional endpoint defenses.
Organizations can reduce exposure by implementing layered security controls.
Cloud providers should continue improving startup verification procedures while organizations should enforce stronger identity validation for privileged accounts.
Continuous stolen credentials monitoring helps identify leaked employee usernames, passwords, API tokens, and cloud credentials before attackers can weaponize them.
Organizations benefit from tracking underground marketplaces where compromised accounts, cloud access, and AI services are advertised.
A real-time dark web monitoring solution enables security teams to identify emerging threats earlier in the attack lifecycle.
Human error remains a significant attack vector. Regular AI Security Awareness Training helps employees recognize increasingly sophisticated phishing messages generated using artificial intelligence.
Routine exposed asset discovery helps identify forgotten servers, exposed cloud services, unsecured APIs, and vulnerable applications before attackers exploit them.
Attackers frequently impersonate trusted organizations when distributing phishing campaigns. Implementing domain abuse monitoring helps identify fraudulent domains that mimic legitimate brands.
Modern phishing campaigns evolve rapidly. Incorporating real time URL scanning into security workflows enables faster identification of malicious websites before users interact with them.
Rather than reacting after compromise, organizations should maintain continuous visibility into criminal forums, credential leaks, malware discussions, and emerging attack infrastructure.
As cybercriminals increasingly leverage cloud infrastructure and AI services, proactive intelligence becomes essential.
DarknetSearch provides organizations with comprehensive cyber threat monitoring capabilities designed to identify external threats before they become internal incidents.
Its proactive monitoring capabilities include:
By identifying early indicators of compromise, organizations can respond before attackers escalate campaigns or weaponize stolen resources.
Businesses seeking to protect business from dark web threats should complement internal security controls with continuous external threat intelligence.
The abuse of cloud startup credits demonstrates how rapidly cybercriminals adapt legitimate technologies for malicious gain. By exploiting promotional cloud resources, attackers obtain inexpensive access to powerful AI platforms capable of accelerating phishing, malware development, fraud, and other criminal operations.
While cloud providers continue strengthening verification processes, organizations cannot rely solely on platform security. Continuous monitoring of leaked credentials, underground marketplaces, external infrastructure, and emerging attack trends remains critical for reducing risk.
As AI becomes increasingly integrated into both business operations and cybercrime, proactive intelligence will play an even greater role in helping defenders stay ahead of evolving threats. 🚨
Is your company exposed to similar risks?
→ Start Free Trial
Disclaimer: DarknetSearch reports on publicly available threat intelligence sources. Inclusion does not imply confirmed compromise.
Discover how CISOs, SOC teams, and risk leaders use our platform to detect leaks, monitor the dark web, and prevent account takeover.
🚀Explore use cases →