The successful outcome of an adversarial attack where an attacker takes unauthorized control of an LLM’s session, context, or connected tools to perform actions on their behalf, including illicit resource consumption.
When a hacker successfully tricks an AI into taking over a user’s session or tools, essentially “steering the wheel” of the AI to do the hacker’s bidding—whether that means stealing data or racking up massive cloud computing bills.
LLM Hijacking refers to the scenario where an adversarial input successfully compromises an AI agent’s operational integrity. Unlike a simple jailbreak (which just forces the model to output restricted text), hijacking implies the attacker has gained functional control. This often occurs in agentic systems where the LLM has access to external tools, APIs, or user-specific data. Once hijacked, the LLM may be coerced into exfiltrating sensitive data, executing unauthorized transactions, modifying system configurations, or illicitly consuming compute resources (a specific variant known as LLMjacking), all while appearing to operate normally to the end user.
For enterprises, LLM Hijacking represents a severe escalation from simple data leakage to active system and financial compromise. If an internal AI assistant has access to CRM data, internal wikis, or financial APIs, a successful hijack can lead to unauthorized data exfiltration or fraudulent transactions. Furthermore, LLMjacking poses a direct financial risk: attackers can hijack an agent to spin up expensive GPU instances or make thousands of LLM API calls, resulting in massive, unexpected cloud bills before the abuse is detected. Mitigating this requires strict Principle of Least Privilege (PoLP), human-in-the-loop (HITL) approvals for high-risk actions, and robust AI Gateway monitoring to detect anomalous tool-use or billing patterns.
In a documented 2026 cloud intrusion (Sysdig Threat Research), an attacker gained initial access via exposed S3 credentials. They hijacked the environment by injecting malicious code into a Lambda function, and then used the compromised identity to illicitly invoke 9 different Amazon Bedrock AI models 13 times. The attacker also attempted to provision expensive p4d.24xlarge GPU instances and deployed a publicly accessible JupyterLab server as a persistent backdoor. This demonstrated how hijacked AI resources can be weaponized for both data theft and massive financial damage.