Security researchers at FortiGuard Labs documented a cloud intrusion in which attackers used a leaked, long-lived AWS IAM access key with AdministratorAccess permissions to create a new IAM user inside the victim organization’s account. They used that access to subscribe to premium foundation models through AWS Marketplace and invoke Claude models via Amazon Bedrock directly, generating inference charges — which can exceed $100,000 per day for heavy Claude 3 Opus usage — billed entirely to the victim, a technique researchers call LLMjacking. Stolen access was resold as discounted AI chatbot subscriptions on Telegram and Discord as part of a wider operation, dubbed Bizarre Bazaar, linked to more than 35,000 attack sessions across 30+ LLM providers. The exact date of the intrusion was not disclosed; it was reported in early September 2026.