INFOSTEALERS are increasingly exposing corporate AI accounts, active sessions and API keys, according to an analysis by SOCRadar of stealer logs collected over 90 days. The research identified 482 companies with exposed AI accounts and credentials; 295 appeared in active logs during the period. The records included 5,434 stealer logs linked to 1,500 distinct corporate email addresses. ChatGPT or OpenAI sessions appeared at 358 companies, representing roughly 90% of the study’s records.
SOCRadar said this reflects widespread shadow-AI use, with employees registering work email addresses on personal devices outside corporate controls, rather than demonstrating a security weakness in OpenAI.
The risk extends beyond password theft. Stolen session cookies can be replayed while still valid, allowing attackers to remain logged in after a password change. Okta researcher Jeremy Kirk, cited by SOCRadar, said a 7 GB stealer dump retrieved from Telegram contained thousands of replayable tokens, including two dozen valid API keys for major AI providers. Compromised accounts may expose conversations containing source code, customer information, contracts and business plans.
Stolen API keys can also enable LLMjacking, in which attackers run AI workloads at the victim’s expense or resell access. Sessions for automation services such as Zapier may provide authorised routes into email, CRM and file-storage systems.
The report recommends bringing AI services under single sign-on, using short-lived sessions, rotating refresh tokens and limiting API keys. Organisations should monitor unusual activity, identify shadow-AI accounts and treat stealer-log exposure as an endpoint incident, not merely a password-reset issue. Anthropic’s response to a reported August session-hijacking incident included invalidating sessions, removing payment methods and notifying affected users.