AI accounts as new goods on the black market. The underground economy has discovered another commodity
AI tools such as ChatGPT, Claude, Microsoft Copilot or Perplexity AI have in a short time become a regular part of work processes. Organizations use them for working with documents, code development, data analysis and internal communication.

AI tools as part of everyday operations
AI tools such as ChatGPT, Claude, Microsoft Copilot or Perplexity AI have in a short time become a regular part of work processes. Organizations use them for working with documents, code development, data analysis and internal communication.
As adoption grows, so does their importance. In many cases they are no longer just supplementary tools but technologies directly involved in teams' day-to-day functioning.
AI accounts appear on the underground
According to analysis by Flare, a trend is emerging in which access to AI services is being offered on underground forums and in closed communities.
These are not isolated cases of abuse. Offers appear repeatedly and have a similar structure to other digital commodities. Access to AI tools is often presented as a product — with emphasis on price, availability, or ease of use.
In some cases these accounts are offered individually, in others as part of larger bundles along with additional infrastructure, such as email accounts or remote access.
There isn’t a single scenario for obtaining accounts
The available data does not directly describe the exact mechanisms by which these accounts are obtained. From the nature of the offers and discussions, however, it appears that it may be a combination of several approaches.
Likely scenarios include the use of compromised credentials, abuse of leaked API keys, or sharing and reselling already existing accounts. In some cases automated registrations or exploitation of promo programs may also play a role.
These mechanisms are not new to cybercrime. What is new is that they are starting to be applied to AI services as well.
Why AI accounts have value
From the perspective of the underground market, AI accounts have several properties that make them an attractive commodity.
Paid versions of AI tools offer higher limits, better performance and broader features. For some users it may therefore be appealing to gain access more cheaply or without the usual restrictions.
Availability of services can also play a role. In some regions or under certain conditions access to AI tools may be limited, which increases the value of existing accounts.
At the same time, for certain types of activity it is easier to use a ready-made access than to repeat the whole registration and verification process.
AI as a tool for scams and attacks
Owning an AI account is not a risk in itself. The problem arises when it is used for malicious activities.
Generative AI makes it quick to create texts for phishing, fraudulent schemes or content for social engineering. The ability to tailor outputs plays a significant role and can increase the persuasiveness of these attacks.
Security organizations have long warned that AI lowers the barrier to entry for cybercrime. It enables even less technically skilled actors to perform activities that previously required a higher level of knowledge.
In addition to text, tools for generating images, audio or video can also be abused, which expands the possibilities for manipulation and impersonation.
Part of a broader cybercriminal ecosystem
Findings indicate that AI accounts are gradually being included among standard items traded on the underground.
Similar to other digital services, they are resold, shared and combined with other infrastructure. AI thus ceases to be only a productivity tool and becomes part of the attack chain.
This development may gradually lower the barrier to entry for additional actors and broaden the range of abuses.
Growing importance of securing AI access
With the increasing importance of AI tools, their secure management will become ever more critical. Account protection, access control and handling of API keys become a key part of a security strategy.
Equally important is educating users and setting rules for working with AI tools, especially when it comes to handling sensitive data.
The trend shows that AI is no longer just a tool for efficiency. It is also becoming a target — and in some cases a means — of cyberattacks.