More than 80,000 corporate domains had employee AI logins stolen by infostealers. SOCRadar analyzed this exposure across major enterprises to map the demand side of credential theft. The findings reveal how shadow AI habits create blind spots for security teams.
SOCRadar started with over one million infostealer records tied to AI services. Researchers narrowed the dataset to 482 major established enterprises to analyze the impact. Out of these organizations, 68% are billion-dollar companies spanning 36 countries and eight sectors, with high concentration in North America.
ChatGPT dominates stealer log findings
The study found 5,434 stealer log records tied to 1,500 distinct corporate email addresses across the 482 companies. Furthermore, 295 of those 482 enterprises surfaced in logs within the last 90 days. A captured ChatGPT or OpenAI session appeared for 358 of the 482 companies. Those specific firms carry roughly 90% of all records in the study.
Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs trail far behind in the dataset. Claude and Gemini do not appear in the top ranks. SOCRadar attributes ChatGPT dominance to first-mover advantage and shadow AI use rather than platform security differences. Employees quietly sign up for tools with work emails on personal devices, feeding infostealer harvests.

Stolen AI sessions grant multi-layered access
A stolen AI cookie provides four capabilities at once: a searchable archive, an execution engine, a billable resource, and an identity. Employees routinely paste source code, customer records, contracts, and unreleased plans into prompts. Attackers replay session tokens to bypass credential authentication, meaning a password reset leaves intruders signed in.
Technology and internet services firms represent the largest group at 144 companies and 40% of all records. Industrials, financial services, retail, healthcare, and energy sectors also appear heavily. LLM platform exposure reaches 93% in energy companies, while agent and automation exposure concentrates in healthcare, financial services, and technology.
CISOs must treat AI platforms with the same security tier as identity providers and code repositories. Anthropic established a template in late August by signing out users, wiping saved payment methods, and refunding unauthorized charges after Claude sessions faced hijacking. Organizations must now identify unmanaged AI usage across endpoints to stop credential reuse.



