SOCRadar’s AI Identity Exposure Report, covered by BleepingComputer, puts a number on something security teams have been quietly dreading: infostealer logs now contain employee logins for AI platforms at serious scale. More than a million records tied to AI services span over 80,000 corporate domains. The researchers narrowed that set to 482 major enterprises and asked one question: when an AI login lands in a stealer log, whose is it, and what does the buyer inherit?

The 482 are not small shops. 68% are billion-dollar organizations spread across 36 countries and eight sectors, and 295 of them surfaced in stealer logs within the last 90 days. Between them sit 5,434 records tied to 1,500 distinct corporate email addresses. This is the demand side of a trade that has been growing all year: on the supply side, infostealers harvest whatever an infected laptop has saved, and AI platform logins are now a large part of that haul.

ChatGPT dominates, and that is a shadow-AI signal

One platform swallows the chart. Captured ChatGPT or OpenAI sessions appear for 358 of the 482 companies, and those companies carry roughly 90% of all records in the study. Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs trail far behind. Claude and Gemini barely register at all.

The researchers read this as a shadow-AI signal rather than a verdict on any vendor’s security. ChatGPT had the first-mover advantage, so far more employees quietly signed up with a work email on a personal device, and that is exactly the population infostealers scrape. As adoption of other assistants catches up, they expect the chart to even out. Anthropic’s own late-August incident backs the point: when infostealer malware started hijacking Claude sessions, Anthropic signed users out, wiped saved payment methods and refunded charges it identified as unauthorized. The platforms without a large corporate footprint today are being targeted the moment they accumulate one.

Why a stolen AI login is worse than a stolen password

A traditional credential unlocks one app. An AI account is four things at once: a searchable archive, an execution engine, a billable resource and an identity. A replayed session hands over all four without a password prompt.

The conversation history alone can be the breach. Employees paste source code, customer records, contracts and unreleased plans into prompts, so the account becomes a store of corporate memory. Whoever replays the session inherits that archive before touching a single internal system, which means the damage starts even if the attacker never reaches your network.

Session cookies walk past MFA entirely. A stolen cookie is a live session, and rotating the password leaves the intruder signed in. The report notes that session tokens and API keys are sought out precisely because they can be replayed to bypass credential-based authentication, which is why password resets are the wrong incident response here.

Then there is LLMjacking. API keys that employees copied into notes apps or workspace settings pages get lifted with everything else, then billed to the victim or resold. Underground vendors sell discounted access to Claude, Gemini and Cursor accounts, some with money-back guarantees. On the agent side, automation platforms hold standing OAuth grants into CRM, email and storage, so a stolen Zapier session lets an attacker build a workflow that exfiltrates data on a schedule, from the vendor’s own trusted IP space.

The exposure is not confined to tech companies

Technology and internet-services firms are the single largest group at 144 companies and 40% of all records, and those firms hold data for many downstream clients, which multiplies the blast radius. Industrials, financial services, retail, healthcare and energy all appear in force. LLM-platform exposure is near-universal and runs highest in energy at 93% of affected companies. Agent and automation exposure, the kind that carries an employee’s authority into other systems, concentrates in healthcare, financial services and technology.

The uncomfortable part is that none of this needs a sophisticated attacker. One employee, one unmanaged laptop, one saved password and a commodity infostealer that has been on sale in Telegram channels since 2022 is enough.

What to actually do

The controls are not exotic. What changed is that AI platforms now belong in the same tier as your identity provider and your code repositories.

Anthropic’s response to its own incident is the template worth copying: invalidate the sessions, strip the payment methods the attackers were abusing, and notify the people whose machines were infected before the fraud reaches them. The report itself is worth a read if you own identity policy, because the numbers are specific enough to put in front of a budget holder.

Leave a Reply

Your email address will not be published. Required fields are marked *