80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Over 80,000 organizations have had AI account credentials and sessions stolen via infostealers, exposing corporate domains to risks including stolen conversation histories and unauthorized use of AI platforms. The majority of stolen credentials relate to ChatGPT/OpenAI, with other platforms like Hugging Face and Replit also affected. Stolen AI sessions bypass password prompts and multi-factor authentication, allowing attackers to access corporate memory, execute automated workflows, and misuse API keys for billing or resale. The exposure spans multiple sectors and countries, with technology firms most affected. Mitigations include enforcing SSO with short-lived sessions, rotating API keys, monitoring session reuse, and identifying shadow AI accounts. Anthropic's response to a similar incident involved invalidating sessions and refunding unauthorized charges, serving as a remediation model.
AI Analysis
Technical Summary
This threat involves widespread theft of AI platform credentials and session tokens from employees across more than 80,000 corporate domains, primarily targeting ChatGPT/OpenAI accounts. Infostealers capture live session cookies and credentials, enabling attackers to bypass authentication controls such as MFA and password changes. The stolen sessions grant access to conversation histories, execution capabilities, billing resources, and identity impersonation. Attackers can leverage stolen OAuth grants in automation platforms like Zapier to exfiltrate data or perform actions with employee authority. The stolen credentials are sold on underground markets, sometimes with money-back guarantees. The exposure affects diverse sectors including technology, healthcare, financial services, and energy. The report emphasizes that AI platforms must be treated as critical identity providers and protected accordingly.
Potential Impact
The impact includes unauthorized access to AI accounts that serve as searchable archives of sensitive corporate data, execution engines for automation, billable resources, and employee identities. Attackers can replay stolen sessions to bypass MFA and password changes, access confidential conversation histories, and abuse API keys for financial gain or further compromise. Automation platforms linked to stolen credentials can be used to exfiltrate data or perform malicious workflows under the guise of legitimate employees. This exposure risks data breaches, intellectual property theft, financial fraud, and operational disruption across multiple industries.
Mitigation Recommendations
Anthropic's approach to invalidating sessions, removing saved payment methods, and refunding unauthorized charges is a recommended remediation model. Organizations should enforce single sign-on (SSO) with OAuth 2.0/OIDC and refresh-token rotation to limit session lifetime. API keys should be scoped, capped, rotated regularly, and monitored for anomalous usage patterns such as access from unfamiliar networks or unusual times. Session tokens should be monitored for reuse or changes in device or geographic fingerprint to detect replay attacks. Treat any employee appearing in stealer logs as an endpoint security incident requiring investigation beyond password resets. Identify and manage shadow AI accounts to prevent unmanaged access. Use tools like SOCRadar’s AI Identity Exposure to detect domain exposure in stolen credential logs.
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Description
Over 80,000 organizations have had AI account credentials and sessions stolen via infostealers, exposing corporate domains to risks including stolen conversation histories and unauthorized use of AI platforms. The majority of stolen credentials relate to ChatGPT/OpenAI, with other platforms like Hugging Face and Replit also affected. Stolen AI sessions bypass password prompts and multi-factor authentication, allowing attackers to access corporate memory, execute automated workflows, and misuse API keys for billing or resale. The exposure spans multiple sectors and countries, with technology firms most affected. Mitigations include enforcing SSO with short-lived sessions, rotating API keys, monitoring session reuse, and identifying shadow AI accounts. Anthropic's response to a similar incident involved invalidating sessions and refunding unauthorized charges, serving as a remediation model.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves widespread theft of AI platform credentials and session tokens from employees across more than 80,000 corporate domains, primarily targeting ChatGPT/OpenAI accounts. Infostealers capture live session cookies and credentials, enabling attackers to bypass authentication controls such as MFA and password changes. The stolen sessions grant access to conversation histories, execution capabilities, billing resources, and identity impersonation. Attackers can leverage stolen OAuth grants in automation platforms like Zapier to exfiltrate data or perform actions with employee authority. The stolen credentials are sold on underground markets, sometimes with money-back guarantees. The exposure affects diverse sectors including technology, healthcare, financial services, and energy. The report emphasizes that AI platforms must be treated as critical identity providers and protected accordingly.
Potential Impact
The impact includes unauthorized access to AI accounts that serve as searchable archives of sensitive corporate data, execution engines for automation, billable resources, and employee identities. Attackers can replay stolen sessions to bypass MFA and password changes, access confidential conversation histories, and abuse API keys for financial gain or further compromise. Automation platforms linked to stolen credentials can be used to exfiltrate data or perform malicious workflows under the guise of legitimate employees. This exposure risks data breaches, intellectual property theft, financial fraud, and operational disruption across multiple industries.
Defensive Guidance
Anthropic's approach to invalidating sessions, removing saved payment methods, and refunding unauthorized charges is a recommended remediation model. Organizations should enforce single sign-on (SSO) with OAuth 2.0/OIDC and refresh-token rotation to limit session lifetime. API keys should be scoped, capped, rotated regularly, and monitored for anomalous usage patterns such as access from unfamiliar networks or unusual times. Session tokens should be monitored for reuse or changes in device or geographic fingerprint to detect replay attacks. Treat any employee appearing in stealer logs as an endpoint security incident requiring investigation beyond password resets. Identify and manage shadow AI accounts to prevent unmanaged access. Use tools like SOCRadar’s AI Identity Exposure to detect domain exposure in stolen credential logs.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6aba7389f7a7c54106c396da
Added to database: 09/28/2026, 14:02:49 UTC
Last enriched: 09/28/2026, 14:03:02 UTC
Last updated: 09/28/2026, 19:06:11 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.