Infostealer Logs Expose AI Credentials from 80,000+ Organizations

Stolen infostealer data exposed AI service credentials from over 80,000 corporate domains, enabling account takeover and LLMjacking attacks.
Infostealer Logs Expose AI Credentials from 80,000+ Organizations
Table of Contents
    Add a header to begin generating the table of contents

    Infostealer malware logs exposed AI account credentials and active sessions tied to more than 80,000 corporate domains, providing attackers with access to ChatGPT, Claude, Gemini, and other AI services used by organizations. SOCRadar security researchers disclosed the findings on September 28, highlighting risks ranging from exposure of stolen conversation history to LLMjacking—hijacking AI accounts to conduct attacks or consume credits.

    Infostealer Malware Harvested Browser Cookies and Saved Passwords for AI Services

    The stolen credentials originated from infostealer malware that harvests browser cookies and saved passwords from infected systems. When employees access AI services through web browsers, the authentication tokens and saved credentials become accessible to infostealer malware running on the same device. The malware collects these artifacts and uploads them to attacker-controlled servers, where they are compiled into logs that are subsequently sold or shared within criminal communities.

    The 80,000+ corporate domains represent organizations where at least one employee device was infected with infostealer malware and had active AI service credentials available for theft. The actual number of individual compromised accounts is likely far higher, as large organizations may have hundreds or thousands of employees using AI services, and a single infected device could expose credentials for multiple users if password managers or shared authentication tokens were harvested.

    Stolen Credentials Enable Multiple Attack Vectors Against Organizations

    Access to stolen AI service credentials enables several distinct attack vectors. Attackers can access conversation histories to extract proprietary business information, source code, or strategic discussions that employees conducted with AI assistants. Many organizations use AI services for drafting communications, analyzing data, or solving technical problems, creating conversation histories that contain sensitive internal information.

    LLMjacking represents a second major risk—attackers can hijack stolen AI accounts to consume the organization API credits or generate malicious content at the victim expense. Organizations with substantial API quotas or unlimited enterprise accounts become targets for attackers who want to use AI services without paying for their own access. The attackers can submit large-scale generation requests, fine-tuning jobs, or embedding computations that exhaust the victim credits or generate costs that the organization must pay.

    Shadow AI Usage Creates Unmonitored Attack Surface

    Many organizations face shadow AI usage—employees adopting AI services without IT approval or governance. These unmanaged AI accounts often use personal email addresses or individual payment methods rather than corporate accounts managed by IT teams. When infostealer malware compromises these shadow AI credentials, the organization may not detect the theft because the accounts are not tracked in corporate identity and access management systems.

    Shadow AI credentials stolen through infostealer campaigns can remain valid and exploitable for extended periods because the compromised users and their organizations do not realize the accounts exist or have been stolen. An employee who signs up for an AI service using their work email but without involving IT creates an account that appears in the 80,000+ domain count but may never be discovered by the organization security team until attackers exploit the access.

    Underground Market for Stolen AI Logins Shows Growing Demand

    SOCRadar analysis of the underground market for stolen AI credentials identified active trading and sales of harvested logins. Attackers value AI credentials for both direct use—conducting their own AI-assisted operations without payment—and for the proprietary information accessible through conversation histories. The growing underground market signals that criminals recognize AI account access as a valuable commodity worth extracting and selling.

    The market emergence also indicates that infostealer malware operators are actively collecting and cataloging AI service credentials as distinct items of value rather than treating them as generic web service logins. This targeted collection suggests that attackers understand the specific risks and opportunities AI credentials present and are optimizing their malware to identify and prioritize these credential types during harvesting operations.

    Organizations Urged to Audit AI Service Usage and Rotate Credentials

    Organizations should audit all AI service usage to identify both officially sanctioned accounts and shadow AI deployments. The audit should catalog which employees have access to AI services, what authentication methods are used, and whether conversation histories contain sensitive information. Discovery of shadow AI accounts should trigger immediate credential rotation and migration to centrally managed enterprise accounts with appropriate access controls and monitoring.

    API keys for AI services should be rotated immediately if there is any indication that employee devices may have been infected with infostealer malware. Session monitoring should be implemented to detect unusual usage patterns that may indicate account compromise, such as API calls from unexpected geographic locations, abnormal generation volume, or access patterns that differ from the legitimate user baseline behavior.

    IT teams should also implement governance policies that require employees to use centrally managed AI service accounts rather than individual consumer accounts. Centralized management allows the organization to monitor for credential theft, enforce security controls like multi-factor authentication, and audit conversation histories for sensitive information exposure. Organizations that leave AI service adoption entirely to individual employees create an unmanaged attack surface that infostealer campaigns can exploit without detection.

    Related Posts