Google says stolen AI accounts sell at up to 99% off, but prices more than doubled
Claude and Gemini logins are what the buyers want most, and coding tools are catching up.
Stolen logins for AI tools are being sold on criminal forums at up to 99% off what the subscription costs, Google says. The figure is in a September 16, 2026 post on Google Cloud's blog, and it applies to consumer accounts.
Reports this weekend, like this one, put it at 97%, a figure from an interview. Google's own posts say 99%, and they also say the price of a stolen account has gone up this year, not down.
- Discount
- up to 99% off retail prices, for consumer accounts
- Price trend
- average price per account more than doubling in 2026
- Most wanted
- Claude and Gemini credentials
- Rising
- Cursor Pro and Devin
Cheaper than retail, pricier than last year
The second number comes from Google's Threat Intelligence Group, in its AI threat tracker published September 8. It counts more people trying to buy AI accounts on the forums it watches, and more selling them.
Based on posts on underground forums tracked by GTIG, buyer demand has increased year-over-year, concentrating heavily on purchasing Claude and Gemini credentials, alongside rising demand for autonomous coding IDEs like Cursor Pro and Devin, reflected in average underground marketplace prices per account more than doubling in 2026.
So both are true at once. A stolen account still costs a sliver of the real thing, and that sliver has more than doubled.
Where the accounts come from
Mostly from infostealers. In May 2026 Google saw the people running one of them, ACRSTEALER, tell it to grab the settings files of two AI coding assistants, Cline and Continue. Those files can hold API keys in plain text, and a key is a direct line to someone else's paid quota.
The bigger version is LLMJacking. In one April case, an attacker got into a company's cloud with an exposed access token and spun up AI infrastructure there. The victim paid for the hardware.
Google also watched a China-linked espionage group use a tool called CC Switch to cycle between Claude, Gemini and Codex, picking whichever model wrote the better exploit script or phishing lure.
Google's advice to companies is to stop treating agent access policies, model inventories and shadow AI, meaning the AI tools staff use without approval, as separate problems.
More on Google
- Google sends its AI chips to orbit next week, ahead of its two-satellite test in 2027September 24, 2026
- UK regulator proposes AI assistants like ChatGPT on Google's choice screens, with a prompt every yearSeptember 23, 2026
- Gemini models explained: 3.8 Flash vs Flash-Lite vs 3.1 Pro, with every release dateSeptember 23, 2026
- Claude Code vs Codex vs Gemini CLI: which plan you need and which models you getSeptember 23, 2026