ThinkFacility
  1. Home
  2. News
  3. Google

Google says stolen AI accounts sell at up to 99% off, but prices more than doubled

Claude and Gemini logins are what the buyers want most, and coding tools are catching up.

Stolen logins for AI tools are being sold on criminal forums at up to 99% off what the subscription costs, Google says. The figure is in a September 16, 2026 post on Google Cloud's blog, and it applies to consumer accounts.

Reports this weekend, like this one, put it at 97%, a figure from an interview. Google's own posts say 99%, and they also say the price of a stolen account has gone up this year, not down.

Discount
up to 99% off retail prices, for consumer accounts
Price trend
average price per account more than doubling in 2026
Most wanted
Claude and Gemini credentials
Rising
Cursor Pro and Devin

Cheaper than retail, pricier than last year

The second number comes from Google's Threat Intelligence Group, in its AI threat tracker published September 8. It counts more people trying to buy AI accounts on the forums it watches, and more selling them.

Based on posts on underground forums tracked by GTIG, buyer demand has increased year-over-year, concentrating heavily on purchasing Claude and Gemini credentials, alongside rising demand for autonomous coding IDEs like Cursor Pro and Devin, reflected in average underground marketplace prices per account more than doubling in 2026.

From GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI | Google Cloud Blog

So both are true at once. A stolen account still costs a sliver of the real thing, and that sliver has more than doubled.

Where the accounts come from

Mostly from infostealers. In May 2026 Google saw the people running one of them, ACRSTEALER, tell it to grab the settings files of two AI coding assistants, Cline and Continue. Those files can hold API keys in plain text, and a key is a direct line to someone else's paid quota.

The bigger version is LLMJacking. In one April case, an attacker got into a company's cloud with an exposed access token and spun up AI infrastructure there. The victim paid for the hardware.

Google also watched a China-linked espionage group use a tool called CC Switch to cycle between Claude, Gemini and Codex, picking whichever model wrote the better exploit script or phishing lure.

Google's advice to companies is to stop treating agent access policies, model inventories and shadow AI, meaning the AI tools staff use without approval, as separate problems.

More on Google

All Google stories