logo

Operation Bizarre Bazaar: Commercialized LLMjacking (Campaign)

ID: 058ddc01-51ca-5a36-b8b7-d5d2131d1498

STIX ID: report--058ddc01-51ca-5a36-b8b7-d5d2131d1498

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Operation Bizarre Bazaar was a large-scale, commercialized LLMjacking campaign (Dec 2025–Jan 2026) in which attackers scanned the internet for misconfigured or unauthenticated LLM and MCP endpoints, validated model access, and resold unauthorized usage via a centralized marketplace. The activity generated tens of thousands of sessions and posed risks beyond compute theft, including exposure of sensitive data in model context windows and potential lateral movement through MCP integrations to internal systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.