Skip to content
SecAIQ

Infostealers Have Exposed AI Logins From Over 80,000 Organizations

Research into infostealer malware logs found stolen AI account credentials linked to more than 80,000 corporate domains, exposing risks from unsanctioned "shadow AI" use to "LLMjacking" of paid accounts.

Written by Safa PAKSU· Published Oct 7, 2026 ·4 min read

Security researchers at SOCRadar have published an analysis of infostealer malware↗ logs showing that login credentials and session data for AI platforms have been stolen from users tied to more than 80,000 corporate domains. The findings follow an incident in late August 2026 in which Anthropic detected hijacked sessions on its platform and responded by signing affected users out, removing stored payment methods, and refunding unauthorized charges. That incident prompted a wider look at how exposed AI accounts are across the corporate world.

What the data shows

SOCRadar reviewed over a million infostealer records and narrowed its focus to 482 larger enterprises for deeper analysis. Among the findings:

  • More than 5,400 stolen credential records were tied to around 1,500 distinct corporate email addresses.
  • Roughly two-thirds of the affected companies are large, billion-dollar organizations spread across dozens of countries.
  • Nearly 300 of the 482 companies studied showed signs of exposure within the previous 90 days, indicating this is an ongoing, active problem rather than old, stale data.
  • The large majority of the analyzed companies (roughly three out of four) had stolen credentials for ChatGPT/OpenAI accounts, which made up the bulk of all records reviewed. Other exposed platforms included Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs.

Researchers noted that other AI assistants appeared far less often in the stolen data, but cautioned this likely reflects smaller adoption footprints in the accounts they sampled rather than stronger security on those platforms.

Two distinct risks: shadow AI and LLMjacking

The report highlights two related but different problems facing organizations:

Shadow AI

This refers to employees signing up for and using AI tools with their work email addresses on personal or unmanaged devices, outside of any policy or oversight from their IT or security teams. Because these accounts sit outside official channels, a company may have no visibility into what data employees have shared with these tools, or that the accounts even exist until they turn up in a stolen-credential dump.

LLMjacking

This term describes attackers using stolen account credentials or API keys to gain unauthorized access to paid AI services. Once inside, attackers may run up usage charges billed to the victim, or resell discounted access to the compromised account to other users, sometimes even offering "refund guarantees" as part of underground marketplaces for stolen AI access.

Who is affected

Exposure was not limited to any single industry. Technology and internet services companies made up the largest single share of affected organizations, but the researchers also found meaningful exposure across industrial, financial services, retail, healthcare, and energy sectors, underscoring that this is a broad, cross-industry issue rather than one confined to tech-heavy companies.

Why it matters

Stolen AI account access can expose far more than a single login. AI assistant accounts often retain conversation history, uploaded documents, and connected integrations, meaning a compromised session could leak sensitive business information, proprietary code, or customer data an employee shared while using the tool. Because many of these accounts were created outside official IT processes, organizations may not even know they need to secure them.

What organizations can do

  • Use single sign-on (SSO) for AI tools where possible, with short-lived sessions rather than long-standing logins that can be replayed by attackers.
  • Scope and rotate API keys used to access AI services, and monitor for unusual access patterns, such as logins from unexpected locations or at odd hours.
  • Watch for shadow AI usage by identifying employee accounts created with corporate email addresses outside sanctioned tools, and bring them under formal policy and monitoring.
  • Check for existing exposure using breach- or exposure-checking services to see whether company domains already appear in infostealer datasets.
  • Educate employees about the risks of installing unverified software or browser extensions, since infostealer malware is most commonly delivered through these channels and can silently harvest saved browser credentials and session cookies.

As AI tools become embedded in everyday work, treating those accounts with the same security rigor as email or financial systems, rather than as low-stakes conveniences, is becoming an essential part of basic organizational hygiene.

Source: BleepingComputer

#infostealer #ai-security #credential-theft #llmjacking #shadow-ai #malware #cloud-security
View as Markdown

Was this helpful?

Share on