Trusence Every claim has a source
Last updated 28 September 2026 Search Türkçe
← All stories
Security

AI credentials found across more than 80,000 corporate domains

Stolen sessions can expose sensitive business information kept in AI conversations, making account theft a data exposure risk.

SOCRadar analyzed over one million infostealer records and found AI-related credentials linked to more than 80,000 corporate domains, narrowing the study to 482 major companies whose stolen logins are being traded. These 482 organizations, 68% of which are billion‑dollar firms across 36 countries, had 5,434 stealer-log entries tied to 1,500 work email addresses, with 295 companies appearing in logs in just the last 90 days. ChatGPT and OpenAI sessions dominate the dataset, appearing for 358 of the 482 companies and representing about 90% of all records, while developer-focused platforms like Hugging Face and Replit also show exposure and Claude and Gemini are largely absent so far. The report stresses that stolen AI sessions are more damaging than traditional passwords because they combine access to chat history, execution capabilities, connected SaaS via agents, and billable API keys, all of which can be abused through replayed session cookies that bypass MFA. Recommended mitigations include putting AI tools behind SSO with short-lived sessions, aggressively scoping and rotating API keys, detecting session-token reuse, treating stealer-log hits as endpoint incidents, and following Anthropic’s example of mass session invalidation and payment-method cleanup after its August 2026 hijacking incident.

Why it matters

For companies, the risk goes beyond someone using an AI service: a stolen session can reveal work already shared with it. That makes protecting AI access part of protecting business information, and supports treating these platforms like identity providers.

Sources

  • BleepingComputer