Infostealer Logs Expose Stolen AI Logins at 482 Enterprises, With ChatGPT Sessions Driving LLMjacking Risk
SOCRadar's AI Identity Exposure Report analyzed 1M+ infostealer records across 80,000+ corporate domains and found exposed AI sessions at 482 major enterprises — 68% of them billion-dollar firms — with ChatGPT/OpenAI sessions at 358 companies carrying roughly…
SOCRadar's AI Identity Exposure Report analyzed more than one million infostealer records tied to AI services spanning 80,000+ corporate domains, narrowing the set to 482 major enterprises, of which 68% are billion-dollar organizations across 36 countries; Security Affairs reports that 295 of those 482 companies appeared in active stealer logs from the last 90 days. ChatGPT/OpenAI sessions were found at 358 of the 482 companies and carried roughly 90% of records, far ahead of Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs; 5,434 stealer-log records mapped to 1,500 corporate email addresses. Both outlets stress that stolen session cookies replay past MFA and remain valid even after password rotation, that OAuth agent grants and stolen Zapier sessions can enable scheduled or automated exfiltration into CRM, email, and storage, and that conversation histories leak pasted source code and customer data. Exposed API keys fuel LLMjacking billed to victims, with underground forums selling Claude keys, ChatGPT cookies, and Cursor sessions — Report 1 notes resales came with money-back guarantees. Anthropic responded in late August to Claude session hijacking — after infostealer malware drained paid usage — by forcing sign-outs and wiping stored payment methods. SOCRadar recommends SSO with short-lived sessions, API key rotation, and stealer-log monitoring. The two reports agree on all overlapping figures; Security Affairs adds the 90-day active-log count and the forum-sales detail.
- SOCRadar analyzed 1M+ infostealer records tied to AI services across 80,000+ corporate domains.
- The affected set was narrowed to 482 major enterprises; 68% are billion-dollar organizations across 36 countries.
- 295 of the 482 companies appeared in active stealer logs from the last 90 days.
- ChatGPT/OpenAI sessions appeared at 358 of the 482 companies, carrying roughly 90% of records.
- Other exposed services included Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs.
- 5,434 stealer-log records mapped to 1,500 corporate email addresses.
- Stolen session cookies bypass MFA when replayed and remain valid after password rotation; rotating passwords leaves intruders signed in.
- Agent OAuth grants can turn one stolen session into scheduled data exfiltration; stolen Zapier sessions can automate exfiltration into CRM, email, and storage.
Coverage timelineoldest first · each row is one article
- · 1d ago80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
BleepingComputer· 58
SOCRadar analysis of over one million infostealer records found stolen AI logins across 80,000+ corporate domains, with ChatGPT sessions dominating LLMjacking exposure.
- · 1d agoAI Accounts Are Becoming the New Target for Infostealers
Security Affairs· 76
SOCRadar found infostealer logs exposing AI sessions and API keys at 482 companies, mostly ChatGPT.