> AI Accounts Are Becoming the New Target for Infostealers
[AUTHOR: Pierluigi Paganini]
[DATE: 28/09/2026 20:14]
[LANGUAGE: EN]
Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems.
SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent rather than the result of historical cleanup. Together, these companies account for 5,434 stealer log records linked to 1,500 distinct corporate email addresses.
The number that really stands out is the ChatGPT figure. A captured ChatGPT or OpenAI session appeared at 358 of the 482 companies, accounting for roughly 90% of all records in the study. Other platforms, including Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs, were far behind.
This doesn’t necessarily point to a security problem with OpenAI. It says more about how employees use AI at work. Many people simply signed up for ChatGPT with a work email and used it on a personal device, often outside company policies and without IT teams even knowing it was happening.
Claude and Gemini barely appear in the data, and SOCRadar is explicit about what that means and what it doesn’t. The researchers read the absence as a shadow-AI signal, not evidence that those platforms are safer to steal from. Anthropic demonstrated that in late August when infostealer malware started hijacking Claude sessions to drain paid usage, forcing a company-wide sign-out, payment method removal, and fraud refunds. Users noticed on Reddit when their usage limits “refilled and then drained” overnight. Claude sessions are targeted the moment they exist in enough volume; there are just fewer of them in corporate environments today.
A stolen AI login is categorically different from a stolen password, and the report makes a clear case for why the industry needs to treat it that way.
“A stolen cookie is a live session. As Okta’s Jeremy Kirk put it, “session tokens and API keys are sought specifically by threat actors because it is often possible to replay those secrets and bypass credential-based authentication.”” reads the report published by SOCRadar. “Rotating the password alone leaves the intruder signed in.”
That quote comes from Okta researcher Jeremy Kirk, cited in the report after Okta’s team pulled a 7 GB stealer dump off Telegram and found thousands of still-replayable tokens inside, including two dozen valid API keys for major AI providers. Rotating the password after a credential theft doesn’t help if the active session cookie is still valid. The attacker stays logged in regardless.
The conversation history inside a compromised AI account creates a different kind of breach. Employees often paste source code, customer data, contracts and unreleased plans into AI prompts without thinking of it as data leaving the company. But once an attacker takes over the session, they can access that entire history without ever breaking into the company’s internal systems. The AI account has effectively become part of the company’s corporate memory, and the stolen session provides access to it.
API keys add a financial risk on top of the data exposure. During July, August and September 2026, underground forums were openly offering Claude API keys, ChatGPT cookies from paid and Pro accounts, and Cursor sessions, in some cases with money-back guarantees. This fuels a type of abuse known as LLMjacking: attackers steal keys from notes, configuration files or workspace settings and use them to run AI workloads at the victim’s expense, or resell the access at a discount. The victim gets the bill. The attacker gets the computing power.
“Keys copied into a notes app or a workspace settings page get lifted with everything else, then billed to the victim or resold. Underground vendors sell discounted access to Claude, Gemini and Cursor accounts and money-back guarantees.” states the report.
Automation platforms make the exposure worse. A stolen Zapier session carries standing authorization into CRM systems, email, and file storage. An attacker with access can build a workflow that exfiltrates data on a schedule, from a trusted vendor IP address, without any further credential theft required.
The sector breakdown is worth noting. Technology firms are the largest group at 144 companies and 40% of all records, which matters because those companies hold downstream client data too. But industrials, financial services, healthcare, retail, and energy all appear in force. Agent and automation exposure, the category that carries an employee’s authorization into other systems, concentrates specifically in healthcare, financial services, and technology, which are exactly the sectors least able to absorb that kind of lateral movement.
All of this is happening while the AI industry debates frontier safety risks, autonomous agent swarms, and the pace of development. That conversation is real and worth having. This report is about something more immediate and considerably more actionable:
You don’t need an autonomous swarm to lose your corporate memory. One employee, one unmanaged laptop, one saved ChatGPT password and a commodity infostealer, widely available in Telegram channels since 2022, can be enough.
The controls recommended in the report are straightforward. Put AI platforms behind single sign-on, use short-lived sessions and rotate refresh tokens so stolen cookies expire quickly. Limit and regularly rotate API keys, and flag activity from unusual locations or outside normal working hours. If an employee shows up in a stealer log, treat it as an endpoint security incident, not simply a password reset. And find shadow AI accounts first: you can’t rotate credentials or secure accounts you don’t even know exist.
Anthropic’s own response to the August incident is the template the report points to: the company didn’t just advise a password change, it invalidated sessions, removed payment methods attackers were abusing, and notified affected users that their machines were compromised. That last step is the difference between a data feed and an actual fire alarm.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, AI accounts)