Skip to main content
Emerging ThreatsData Breaches

Stolen AI Logins Expose 80,000+ Organizations to Data Breach Risk

Corporate office interior with blurred workers and a laptop on a desk.

"Session tokens and API keys are sought out precisely because they can be replayed to bypass credential-based authentication," Okta's Jeremy Kirk warned — and the summer of 2026 turned that warning into hard data.

SOCRadar's sweep: scope, scale, and a 482-company focus

SOCRadar began with more than one million infostealer records tied to AI services found across 80,000-plus corporate domains and narrowed the set to 482 established enterprises to answer one question: when an AI login turns up in a stealer log, whose is it and what does a buyer inherit? Of those 482 companies, 68% are billion‑dollar organizations spanning 36 countries and eight sectors. Together they account for 5,434 stealer-log records tied to roughly 1,500 distinct corporate email addresses; 295 of the 482 surfaced in the last 90 days.

Platform exposure: ChatGPT dominates, developer tools show up too

The dataset is heavily skewed toward one vendor. A captured ChatGPT or OpenAI session appears for 358 of the 482 companies, and those companies represent roughly 90% of all records in the study. Trailing names include Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs — indicating developer tools and automation platforms are also exposed. Notably absent from the top ranks were Claude and Gemini; Anthropic’s late‑August incident, reported by BleepingComputer, demonstrates that Claude sessions are targeted the moment they exist in sufficient volume, but Claude simply has a smaller corporate footprint to harvest today.

Why a stolen AI login is worse than a stolen password

SOCRadar frames an AI account as four things at once: a searchable archive, an execution engine, a billable resource and an identity. A stolen session hands over all four without a password prompt. Conversation histories can contain source code, customer records, contracts and unreleased plans; whoever replays the session inherits that corporate memory before they touch internal systems. Session cookies are live sessions: as Jeremy Kirk noted, they can be replayed to bypass credential-based authentication and often survive a password rotation. Agents and automation platforms carry standing OAuth grants into CRM, email and storage — a stolen Zapier session can let an attacker build workflows that exfiltrate data using the employee’s authority. API keys copied into notes or workspace settings become money, compute capacity and cover: underground vendors sell discounted access to Claude, Gemini and Cursor accounts and tout money‑back guarantees in a practice the report calls LLMjacking.

Sectoral risk: technology, energy, healthcare, financial services

Technology and internet-services firms are the largest single group — 144 companies and 40% of all records — and they often hold data for downstream clients. Industrials, financial services, retail, healthcare and energy also appear in force. The risk profile shifts by sector: LLM-platform exposure is near‑universal and is highest in energy (93% of affected companies), while agent and automation exposure — the kind that carries an employee's authority into other systems — concentrates in healthcare, financial services and technology.

Controls to deploy right now: SSO, key hygiene, and session monitoring

  • Put every AI platform behind SSO with short‑lived sessions: use OAuth 2.0/OIDC with refresh‑token rotation so a stolen cookie expires before it can be sold. SOCRadar notes that SSO removes the saved password but does not neutralize existing live session cookies or accounts opened before the policy.
  • Scope, cap and rotate API keys: the report recommends alerting on usage from unfamiliar ASNs or at odd hours as the fingerprint of LLMjacking.
  • Monitor for session‑token reuse and replay: a session that changes country or device fingerprint mid‑life is likely replayed. SOCRadar says to treat any employee appearing in a stealer log as an endpoint incident, not merely a password reset.
  • Find shadow accounts first: you cannot rotate what you don't know exists. SOCRadar points to its free AI Identity Exposure tool to find which of your domains already appear in stealer logs.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams will need to treat AI platforms like identity providers and code repositories — implementing SSO with refresh‑token rotation, session monitoring and API‑key scoping.
  • Procurement and enterprise leaders should expect to ask vendors about session lifetimes, token rotation and auditability, because the exposure follows the users more than the platform.
  • End users should assume conversation histories and saved keys are sensitive corporate assets; a single unmanaged laptop with a saved ChatGPT session and a commodity infostealer — on sale in Telegram channels since 2022, SOCRadar notes — is enough to seed a breach.

Anthropic’s late‑August response holds a practical template: it signed users out, wiped saved payment methods, refunded charges it identified as unauthorized and notified infected users before fraud escalated. The lesson from SOCRadar’s dataset is equally plain — AI identities sit at the intersection of memory, execution, billing and authority, and the controls are familiar even if the surface is new. Treat those accounts accordingly.

Source: BleepingComputer / SOCRadar AI Identity Exposure Report