---
title: "Threat briefing: How attackers compromise non-human identities for LLMHijacking - Oct 30"
description: Learn how threat actors have been have been using non-human identities to hijack AI infrastructure and how to defend against it.
image: https://hero.permiso.io/hubfs/thief%202.png
---

** [![Permiso](https://hero.permiso.io/hubfs/Permiso%202023.03.30/images/logo-permiso-dark.svg) ](https://permiso.io/?hsLang=en) **

Menu

** [![Permiso](https://hero.permiso.io/hubfs/Permiso%202023.03.30/images/logo-permiso-light.svg) ](https://permiso.io/?hsLang=en) **

- [ Product ](https://permiso.io/product/?hsLang=en)
- [ About ](https://permiso.io/about/?hsLang=en)
- [ P0 Labs ](https://permiso.io/p0-labs/?hsLang=en)
- [ Resources ](https://permiso.io/product/?hsLang=en)
- [ Contact ](https://permiso.io/contact/?hsLang=en)

[ Sign in ](https://arbiter.permiso.io/)

- [** ](https://twitter.com/permisosecurity)
- [** ](https://www.linkedin.com/company/permiso-security/)

© Permiso Security 2022  |  [Privacy Policy](https://permiso.io/legal/privacy?hsLang=en)  |  [Terms](https://permiso.io/legal/terms?hsLang=en)

# Threat Briefing: How Attackers Leverage Non-Human Identities for LLMjacking

###### Wed Oct 30 at 9am PT/12pm ET![thief 2](https://hero.permiso.io/hs-fs/hubfs/thief%202.png?width=615&height=346&name=thief%202.png)

In this threat briefing, Ian Ahl, SVP of P0 labs and former Head of Advanced Practices at Mandiant, will walk through how threat actors have honed how they leverage compromised non-human identities like API keys and access tokens. From SES abuse, to cryptomining, to now LLMjacking, threat actors follow where the money goes. Ian will demonstrate how modern threat actors are LLMjacking hosted models to run dark roleplaying services, and rack up compute costs along the way. Join this public threat briefing to learn:

- How attackers compromise non-human identities for hijacking victim GenAI infrastructure to power their own LLM applications.
- What Permiso captured from a full prompt and response log from a recent campaign.
- How to defend against the common resource hijacking attacks in AWS and other cloud providers.

So bring some teammates and walk away with a crash course in how to bolster your defenses against advanced threat actor groups. 

### Sign Up for The Threat Briefing

##### Your CloudSec Expert

###### ![IanAvatar](https://hero.permiso.io/hs-fs/hubfs/IanAvatar.png?width=120&height=119&name=IanAvatar.png)

###### **Ian Ahl**

###### **SVP of P0 Labs**

"P0 labs is at the forefront of understanding attacks by making identity a pillar in their research of threat actors like LUCR-3, aka Scattered Spider."

![Headshot-Default-Jason Chan-1](https://hero.permiso.io/hubfs/Headshot-Default-Jason%20Chan-1.png)

Jason Chan, Former Head of Security at Netflix

"The PO Labs continues to impress us by being at the forefront of these emerging cloud attacks. The knowledge they're able to share with our team on the TTPs of modern threat actors like Scattered Spider is unlike anything we've seen before."

![Headshot-Default-Rob Preta](https://hero.permiso.io/hubfs/Headshot-Default-Rob%20Peralta.png)

Rob Preta, Head of Cyber Security at ACV Auctions

"Permiso provided insights into managed and unmanaged risk areas that we didn't previously have."

![Michael H](https://hero.permiso.io/hubfs/Michael%20H.png)

Michael Hensley, Head of Cyber Security at Modern Health

###### trusted by these cool companies

- ![modern-health](https://hero.permiso.io/hubfs/Permiso%202023.03.30/images/logo-modern-health.svg)
- ![Coupa](https://hero.permiso.io/hubfs/Permiso%202023.03.30/images/logo-coupa.svg)
- ![Nutanix](https://hero.permiso.io/hubfs/Permiso%202023.03.30/images/logo-nutanix.svg)
- ![ACV](https://hero.permiso.io/hubfs/Permiso%202023.03.30/images/logo-acv.svg)

### Your Cloud Security Expert

![Ian](https://hero.permiso.io/hubfs/Permiso_Security_June2023/images/Ian.png)

**IAN AHL**

*SVP of P0 Labs*

Former Head of Advanced Practices at Mandiant (10 years)

Incident Response Extraordinaire

Former TekDefense

USMC 

** [![Permiso](https://hero.permiso.io/hubfs/Permiso%202023.03.30/images/logo-permiso-light.svg) ](https://permiso.io/?hsLang=en) **

- [ Product ](https://permiso.io/product/?hsLang=en)
- [ About ](https://permiso.io/about/?hsLang=en)
- [ Join Our Team ](https://permiso.io/product/?hsLang=en)

- [ P0 Labs ](https://permiso.io/p0-labs/?hsLang=en)
- [ Cloud Incident Report ](https://permiso.io/p0-labs/services/cloud-incident-response/?hsLang=en)
- [ Resources ](https://permiso.io/p0-labs/?hsLang=en)

- [ Request a Demo ](https://permiso.io/?hsLang=en#get-in-touch)
- [ Contact us ](https://permiso.io/contact/?hsLang=en)
- [ Sign In ](https://arbiter.permiso.io/account/login)

- [** ](https://twitter.com/permisosecurity)
- [** ](https://www.linkedin.com/company/permiso-security/)

© Permiso Security 2023  |  [Privacy Policy](https://permiso.io/legal/privacy?hsLang=en)  |  [Terms](https://permiso.io/legal/terms?hsLang=en)