← All research

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

2026-09-29 · OrangeStealth Security

An AI login is no longer just another password to reset. It can expose conversation history, connected applications, API spending and the employee identity attached to all of them.

BleepingComputer reports on SOCRadar research that began with more than one million infostealer records tied to AI services across more than 80,000 corporate domains. Researchers then examined 482 major enterprises in greater detail. Within that group, they identified 5,434 records tied to 1,500 distinct corporate email addresses, with 295 of the companies appearing in records from the previous 90 days.

X
Xavier Rivera@xavierriverax

SOCRadar found AI logins for 80,000+ corporate domains in infostealer logs, then dug into 482 major firms with 5,434 stolen records.ChatGPT sessions cover 358 of

September 28, 2026 · Excerpt; read original

The dataset was heavily concentrated around ChatGPT and OpenAI accounts. At least one captured credential or session associated with those services appeared for 358 of the 482 companies, accounting for roughly 90 percent of records in the study. Other exposed services included Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs.

That concentration should not be interpreted as proof that one AI provider is inherently less secure than another. The researchers framed it as a shadow AI problem: widely adopted services accumulate more employees using work addresses on personal or unmanaged devices. Infostealers target the endpoint and its stored credentials or active sessions, so exposure tends to follow user behavior.

One employee, one unmanaged laptop, one saved ChatGPT password and one commodity infostealer that has been on sale in Telegram channels since 2022 is enough.

BleepingComputer

What makes an AI session different

A stolen AI account can contain far more than access to a chatbot. Conversation histories may hold pasted source code, contracts, customer information, internal plans or troubleshooting details. API keys can create unexpected usage charges. Automation tools may also have standing permission to interact with email, cloud storage, customer systems or other services.

Session theft is especially important. An infostealer may capture a live cookie or token that can be replayed without entering the account password again. Changing the password may therefore be insufficient unless active sessions and related tokens are also revoked. The report describes abuse of stolen API access for unauthorized model usage as LLMjacking.

None of these findings proves that every listed organization suffered an internal breach. A stealer log associated with a corporate address is an exposure signal that requires validation and investigation. A configuration gap is not proof of compromise, and the presence of a work domain does not establish what information an attacker accessed.

B
BleepingComputer@bleepincomputer

🤖 Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains.🔍 @socradar examines how stolen AI logins can expose chats,

September 28, 2026 · Excerpt; read original

A hypothetical example

Hypothetical: An employee creates an AI account with a company email address on a personal laptop. They paste a draft customer agreement into a conversation and save an API key in a notes application. Malware later captures the active AI session and the saved key. Even if the company uses multifactor authentication elsewhere, the stolen session could expose previous conversations, while the key could be used to generate charges.

The right response would extend beyond resetting one password. The organization would need to revoke active sessions, rotate the exposed key, examine the laptop, review account activity and determine whether sensitive information appeared in conversation history.

The fix, in order

  1. Inventory company AI use. Identify approved platforms, accounts created with corporate domains, browser extensions, developer tools and automation services. Ask employees what they actually use, since procurement records will not reveal every shadow account.

  2. Centralize access where possible. Put approved services behind company identity controls and use short session lifetimes where supported. Remember that single sign on can reduce saved passwords but does not automatically neutralize an already stolen session cookie.

  3. Restrict and rotate API keys. Give keys only the permissions and spending capacity required. Keep them out of notes, chat histories and source repositories. Review usage for unusual locations, networks, times or sudden volume changes.

  4. Treat stealer exposure as an endpoint incident. Revoke sessions and tokens, investigate the device, rotate relevant credentials and review connected applications. A password reset alone may leave active access intact.

  5. Set clear data rules. Tell employees what information may never be entered into public AI services, then provide an approved alternative that supports real workflows.

A passive, external-only External Security Posture Assessment can help identify visible account and domain exposure without attempting access, but internal ownership still matters. Security, IT and business leaders need a shared list of approved services and a defined response when an employee account appears in a stealer log.

Start this week by listing every AI and automation platform your staff uses, then verify who owns each account, what it can access and how you would revoke every active session today.