Security teams at the Black Hat conference described employee AI accounts and corporate model access as a growing target for attackers. Stolen credentials can hide malicious activity inside services that organizations already expect employees and agents to use. More than twenty thousand attendees were expected at Black Hat in Las Vegas. Researchers said stolen ChatGPT, Claude and Gemini credentials are bought and resold.

One reported LLM-jacking campaign sent nearly two hundred thousand API requests in two minutes. CrowdStrike reported an eighty-nine percent increase in attacks using AI to scale or target operations. The source record attributes statements, allegations and official descriptions to the people or institutions making them.

Stolen cloud credentials produced similar abuse patterns during earlier cloud adoption. AI agents may operate at unusual hours without automatically indicating compromise. Token and cost logs provide partial oversight but do not fully capture permissions or intent. This background supplies chronology and operating context without deciding the outcome still under review.

Companies continue to find unapproved shadow AI tools on internal networks. Security products for monitoring agent identity and out-of-bounds behavior remain under development. Counts, dates and legal status remain tied to the checked source record because later reporting can revise preliminary information.

The evidentiary limit is specific: The figures came from vendors and conference reporting and do not establish a universal enterprise incident rate. The available reporting does not support an inference beyond that boundary.

The next record points are independent incident reporting on AI account compromise and deployment of agent-specific identity and permission controls. Each can be checked against later official documents or independent reporting.

The verified chronology is therefore limited to the following: More than twenty thousand attendees were expected at Black Hat in Las Vegas. Researchers said stolen ChatGPT, Claude and Gemini credentials are bought and resold. One reported LLM-jacking campaign sent nearly two hundred thousand API requests in two minutes. CrowdStrike reported an eighty-nine percent increase in attacks using AI to scale or target operations. Companies continue to find unapproved shadow AI tools on internal networks. Security products for monitoring agent identity and out-of-bounds behavior remain under development. The relevant context is Stolen cloud credentials produced similar abuse patterns during earlier cloud adoption. AI agents may operate at unusual hours without automatically indicating compromise. Token and cost logs provide partial oversight but do not fully capture permissions or intent. These details state what the sources establish and preserve what remains unknown.