Infostealer malware has found a new favorite target: the login sessions employees use for ChatGPT, Claude, and dozens of other AI tools. A large-scale sweep of criminal credential markets has traced more than a million stolen AI-service records back to over 80,000 organizations worldwide — turning "shadow AI" from a policy headache into an active breach vector.
What happened
Stealer-log markets — the same underground data dumps that feed most modern credential-stuffing and session-hijacking attacks — were combed for anything tied to AI platforms. The result: more than a million records connecting stolen logins and live sessions to upwards of 80,000 companies. Narrowed to 482 large corporate domains, the picture sharpens further: 68% of those companies are billion-dollar enterprises, spread across 36 countries and eight industry sectors, and nearly 300 of the 482 had fresh exposure in just the last 90 days.
Broken down by platform, one name dominates. ChatGPT/OpenAI sessions turned up in 358 of the 482 companies studied — roughly 70% of the sample — with Zapier, Hugging Face, Replit, Notion, Lovable, and ElevenLabs trailing well behind. Google's Gemini, notably, doesn't appear in the dataset at all.
That gap says less about which AI vendor is "more secure" and more about adoption timing. ChatGPT's head start means far more employees signed up early using a work email on a personal or unmanaged device — exactly the population infostealers are built to catch. A separate incident involving hijacked Claude sessions in late August showed the same dynamic can hit any assistant once its user base is large enough to be worth targeting.
Tech and internet-services companies make up the single largest exposed group — 144 companies and roughly 40% of all records — but industrials, financial services, retail, healthcare, and energy all show up in force. This isn't a tech-sector problem; it's an "everyone with employees who use AI tools" problem.
Why it matters
A stolen password gets an attacker one door. A stolen AI session hands over four things at once, with no second prompt required:
- An archive — chat history full of pasted source code, customer data, contracts, and unreleased plans.
- An execution engine — the ability to keep the conversation going and act on what's stored there.
- A billable resource — API keys and credits that can be resold or burned for LLMjacking.
- An identity — connected integrations and, increasingly, autonomous agents acting with the employee's own authority.
Session cookies make it worse: a live session bypasses MFA entirely, since the token was already validated. Rotating the password afterward does nothing — the attacker is already through the door. And AI agents wired into CRMs, email, or cloud storage inherit whatever access the compromised account had, letting a single stolen session turn into unsupervised, scheduled data exfiltration.
None of this requires a sophisticated operation. One employee, one unmanaged laptop, one saved password, and a commodity infostealer — a malware class that's been sold on Telegram since 2022 — is enough to put a company on this list.
What to do about it
- Put every AI platform behind SSO with short-lived sessions. OAuth 2.0/OIDC with refresh-token rotation means a stolen cookie expires before it's useful, and removes the saved password entirely. It won't retroactively fix accounts opened before the policy existed, so audit those separately.
- Scope, cap, and rotate API keys. Alert on usage from unfamiliar ASNs or off-hours activity — the classic fingerprint of LLMjacking.
- Treat session-token reuse as an incident, not a login. A session that changes country or device fingerprint mid-life is a replayed token, not routine activity — investigate it as one.
- Find your shadow AI accounts before an attacker does. You can't rotate credentials for accounts you don't know exist. Inventory which AI tools employees have signed up for, and on which devices, before assuming an official SSO rollout covers everyone.
The takeaway isn't "switch to a safer assistant." Every major AI platform shows up in this dataset, and the ranking simply tracks who has the most users today. The exposure follows the people, not the product — and it shows up wherever identity policy hasn't reached yet.
