Stolen AI Logins Expose Corporate Data, Cloud Accounts and Employee Identity
In the summer of 2026, a new term emerged in the security industry: “stolen AI logins.” In late August, Anthropic responded to an infostealer’s hijacking of Claude sessions by signing users out, removing stored payment methods and refunding fees it determined were fraudulent.
That is the supply side of the problem. SOCRadar’s AI ID Exposure Report examines the demand side: companies whose employees’ AI credentials are being sold.
Starting with more than 1 million information-stealing records associated with AI services across more than 80,000 company domains, the study analyzed 482 leading companies and answered one question: If an AI login appears in a theft log, who does it belong to, and what can an attacker inherit?
Of the 482 companies, 68% are multibillion-dollar organizations spanning 36 countries and eight sectors. The organizations are concentrated in North America, and dozens are ranked by Forbes.
Across these companies, the study identified 5,434 stealer-log records associated with 1,500 individual corporate email addresses. Of the 482 companies, 295 appeared in records collected during the previous 90 days.
ChatGPT dominates stolen AI login data
When the records are categorized by platform, one name dominates the dataset. Captured ChatGPT or OpenAI sessions appeared at 358 of the 482 companies, which together accounted for approximately 90% of all records studied. Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs appeared far less frequently.

The absence of some major AI platforms is also notable. Claude and Gemini do not appear at the top of the dataset.
|
Researcher’s comments “We see ChatGPT’s near-total dominance as a signal of shadow AI, not a verdict on the vendor’s security. Its first-mover advantage means far more employees are secretly signing up for work email on personal devices, and that’s the population information thieves are harvesting from. We expect this graph to even out as adoption of other assistants catches up.” |
Anthropic’s incident in late August offers a timely warning: once Claude sessions are present in sufficient numbers, they become a target. For now, the platform may simply have a smaller footprint among the companies represented in the study.
The lesson for CISOs is not to choose one AI assistant over another based solely on this dataset. Exposure follows the user, including users who operate outside corporate security policies.
Enter one work domain to see which AI platforms are displaying stolen employee logins, how many records are associated with it and which information is current.
No signup is required. The tool is updated daily across 44 AI platforms.
Why a stolen AI login can be worse than a stolen password
A traditional credential may unlock one application. An AI account can combine four valuable assets: a searchable archive, an execution engine, billable resources and an employee’s identity. A stolen session can provide access to all four without requiring the attacker to enter a password.
1. Conversation history can expose sensitive business information
Employees may paste source code, customer records, contracts and unannounced plans into AI prompts. As a result, an AI account can become a storehouse of corporate memory. Anyone replaying a stolen session may inherit that archive before attempting to access other systems.
2. Session cookies can bypass MFA protections
Stolen cookies can represent live sessions. As Okta’s Jeremy Kirk notes, session tokens and API keys are valuable to attackers because they can be reused or regenerated to bypass credential-based authentication. Changing a password may not sign out an intruder who still has an active session.
3. AI agents can act with an employee’s authority
Automation platforms can maintain persistent OAuth permissions for CRM systems, email and storage. A stolen Zapier session could allow an attacker to create a workflow that removes data from a vendor’s trusted IP space on a scheduled basis.
4. API keys can enable LLMjacking
API keys copied to a Notes app or workspace settings page may be stolen along with other credentials. Attackers can use the keys to generate charges for the victim, consume available capacity or resell access. Underground vendors sell discounted access and money-back guarantees for Claude, Gemini and Cursor accounts.

Technology leads, but every major industry is exposed
Technology and Internet services companies formed the largest group in the study, with 144 companies accounting for 40% of all records. These organizations may also hold data belonging to many downstream customers.
Industrials, financial services, retail, healthcare and energy companies also appear in the records.

Looking at the same sectors by the types of AI services at risk changes the picture. Exposure to large language model platforms is nearly universal. Energy had the highest reported exposure, with LLM platforms affected at 93% of companies in the sector.
The risks associated with agents and automation that transfer employee privileges to other systems are concentrated in healthcare, financial services and technology.

These attacks do not require a swarm of autonomous agents. One employee, one unmanaged laptop, one saved ChatGPT password and one commodity infostealer can be enough to create exposure.
How organizations can reduce stolen AI account exposure
The necessary controls are not exotic. AI platforms now belong in the same security layer as identity providers and code repositories.
- Put AI platforms behind SSO and use short-lived sessions. Use OAuth 2.0/OIDC and refresh-token rotation so stolen cookies expire before they can be sold. SSO can eliminate saved passwords, but it does not invalidate live session cookies or address accounts created before the policy was introduced.
- Scope, cap and rotate API keys. Monitor for usage from unfamiliar autonomous system numbers (ASNs) or unusual times, which may indicate LLMjacking.
- Monitor session-token reuse. A session that changes country or device fingerprint during its active period may indicate a replayed session. Employees whose accounts appear in stealer logs should be treated as endpoint-incident cases, not merely as password-reset cases.
- Find shadow AI accounts first. Organizations cannot rotate credentials they do not know exist. Identify company domains already listed in stealer logs with SOCRadar’s Free AI Identity Exposure Tool.
Stolen AI sessions require an identity-focused response
Anthropic’s response to its own incident provides a useful template. The company invalidated sessions, removed payment methods that attackers were exploiting and notified people whose machines were infected before fraud reached them.
As AI services become part of everyday business workflows, stolen AI logins can expose more than a single application. They can reveal conversations, consume cloud resources, preserve access to connected systems and provide attackers with an employee’s digital identity.
Read the full SOCRadar AI ID Exposure Report.
Sponsored and written by SOCRadar.
Source: www.bleepingcomputer.com


