Cyber Magazine October 2026 | Page 30

THE CYBER INTERVIEW
Once the attacker does get access to enterprise AI systems however,“ they use the victim’ s tools and burn through their tokens”.“ So they have got a double cost,” Zeki says.“ The cost of the AI usage being used by the adversary, but then also the ransomware payment they’ ll get later on as well.” This way of hijacking enterprise models( LLM jacking) and running up their bills causing financial harm is called cost harvesting. In CrowdStrike’ s Threat Hunting Report, it mentions such a campaign where the attackers sent around 200,000 API requests in two minutes!
Zeki notes that this is no different from when crypto mining became popular and“ lots of organisations were having their web servers compromised just to have crypto miners deployed”.
The solution again comes around to being able to see what is happening.“ At CrowdStrike, we are big believers of making sure we can secure and protect the technologies that organisations are using,” Zeki says.“ So when it comes to AI, what we have is a platform that allows us to actually connect and integrate the many different ways that organisations may be utilising AI – all the way down from the endpoint level access, up to AI usage in SaaS platforms. And that allows us to get really good, strong coverage of how AI is being used across the organisation.”

“ I say this every year, but the reality is, it is always going to get worse, unfortunately”

Zeki Turedi Field Chief Technology Officer for Europe CrowdStrike
WATCH NOW
CrowdStrike – Defending against AI-powered cyber threats at machine speed
30 October 2026