Microsoft Busts Hackers Selling Illegal Azure AI Access
ID: e3187d19-e859-5206-9bcf-5ed8fca3b37c
STIX ID: report--e3187d19-e859-5206-9bcf-5ed8fca3b37c
Feed Name: Dark Reading
Date Published: 2025-02-28
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Microsoft's digital crimes unit identified and publicly named individuals linked to an LLMjacking campaign (Storm-2139) that harvested exposed API keys to sell unauthorized access to Azure AI services and manipulate models to produce illicit content; Microsoft filed lawsuits and seized infrastructure. The report details attacker methods (credential scraping, resale of access, bypassing model safeguards), real-world impacts (illegal imagery generation, resale on illicit marketplaces, doxxing), and recommends mitigations such as least-privilege access, vaulting API keys, and strong authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
