More Than 80,000 Organizations Had AI Logins Stolen by Infostealers
AI

More Than 80,000 Organizations Had AI Logins Stolen by Infostealers

TechNews Editorial
TechNews EditorialSep 28, 2026 · 2 min read
Share

Why it matters

Stolen AI sessions hand attackers corporate memory, billing resources, and automation grants without requiring a password prompt.

The facts

  • Over 80,000 corporate domains had employee AI logins appear in infostealer logs.
  • ChatGPT sessions made up roughly 90% of all records across studied major enterprises.
  • Stolen AI sessions bypass passwords and expose corporate data archives and automation tokens.

More than 80,000 corporate domains had employee AI logins stolen by infostealers. SOCRadar analyzed this exposure across major enterprises to map the demand side of credential theft. The findings reveal how shadow AI habits create blind spots for security teams.

SOCRadar started with over one million infostealer records tied to AI services. Researchers narrowed the dataset to 482 major established enterprises to analyze the impact. Out of these organizations, 68% are billion-dollar companies spanning 36 countries and eight sectors, with high concentration in North America.

ChatGPT dominates stealer log findings

The study found 5,434 stealer log records tied to 1,500 distinct corporate email addresses across the 482 companies. Furthermore, 295 of those 482 enterprises surfaced in logs within the last 90 days. A captured ChatGPT or OpenAI session appeared for 358 of the 482 companies. Those specific firms carry roughly 90% of all records in the study.

Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs trail far behind in the dataset. Claude and Gemini do not appear in the top ranks. SOCRadar attributes ChatGPT dominance to first-mover advantage and shadow AI use rather than platform security differences. Employees quietly sign up for tools with work emails on personal devices, feeding infostealer harvests.

An intruder uses a stolen AI session to browse an employee’s conversation archive and download confidential attachments.
Illustration: AI & Tech News

Stolen AI sessions grant multi-layered access

A stolen AI cookie provides four capabilities at once: a searchable archive, an execution engine, a billable resource, and an identity. Employees routinely paste source code, customer records, contracts, and unreleased plans into prompts. Attackers replay session tokens to bypass credential authentication, meaning a password reset leaves intruders signed in.

Technology and internet services firms represent the largest group at 144 companies and 40% of all records. Industrials, financial services, retail, healthcare, and energy sectors also appear heavily. LLM platform exposure reaches 93% in energy companies, while agent and automation exposure concentrates in healthcare, financial services, and technology.

CISOs must treat AI platforms with the same security tier as identity providers and code repositories. Anthropic established a template in late August by signing out users, wiping saved payment methods, and refunding unauthorized charges after Claude sessions faced hijacking. Organizations must now identify unmanaged AI usage across endpoints to stop credential reuse.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading