The Stolen AI Login: 80,000 Domains in Stealer Logs and the Session MFA Cannot Save

In late August, Anthropic responded to infostealer-driven hijacking of Claude sessions by signing users out, wiping saved payment methods, and refunding charges it identified as unauthorized. That was the supply side — the platform cleaning up after its sessions were stolen. On 28 September 2026, SOCRadar published the demand side: its AI Identity Exposure Report starts from more than one million infostealer records tied to AI services across 80,000-plus corporate domains, then narrows to 482 major enterprises to answer what a buyer actually inherits when an employee’s AI login lands in a stealer log.

The answer is the thesis of this briefing: a stolen AI login is not a password. It is a searchable archive, a live session that walks past MFA, a set of standing agent authorizations, and a billable resource — all four at once, with no password prompt.

The dataset, and why the 482 matter more than the million

A million stealer-log rows is easy to dismiss as noise — old dumps, duplicates, consumer accounts. SOCRadar’s filtering is the part worth taking seriously: of the 482 enterprises in focus, 68% are billion-dollar organizations across 36 countries and eight sectors, dozens of them Forbes-ranked. Between them sit 5,434 stealer-log records tied to 1,500 distinct corporate email addresses, and 295 of the 482 surfaced in the last 90 days. That recency figure is doing the heavy lifting — this is not archaeology, it is active, ongoing credential theft hitting large organizations right now.

Break the set down by platform and one name swallows the chart. A captured ChatGPT or OpenAI session shows up for 358 of the 482 companies, carrying roughly 90% of all records in the study. Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs trail far behind. Conspicuously absent from the top ranks: Claude and Gemini.

ChatGPT’s dominance is a shadow-AI signal, not a vendor verdict

The easy misreading is “OpenAI is the problem.” SOCRadar’s own framing, echoed by independent coverage, is more uncomfortable and more useful: ChatGPT dominates because its first-mover advantage means far more employees quietly signed up with a work email on a personal device — exactly the population commodity infostealers scrape. Infostealers do not hack the AI vendor; they harvest what is already sitting on the endpoint.

The caveat cuts both ways, and Anthropic’s own late-August incident proves it: Claude sessions are targeted the moment they exist in enough volume. The platform simply has a smaller corporate footprint to harvest today, and as adoption of other assistants catches up, the chart should even out. The lesson for a CISO is not “pick a safer assistant.” It is that exposure follows the users, and the users are everywhere your policy isn’t — the same shadow-AI dynamic we documented in the Vercel breach, where a shadow AI tool became an identity-based supply-chain pivot.

Why a stolen AI session beats a stolen password four ways

The report structures the damage as four inheritances, and each one defeats a different assumption in the standard “reset the password” playbook:

  • The conversation history is the breach. Employees paste source code, customer records, contracts, and unreleased plans into prompts. Whoever replays the session inherits that corporate memory before touching a single internal system.
  • Session cookies walk past MFA. A stolen cookie is a live session, not a credential guess. As Okta’s Jeremy Kirk is quoted in the coverage, session tokens and API keys are sought precisely because they replay past credential-based authentication — rotating the password leaves the intruder signed in.
  • Agents act with the employee’s authority. Automation platforms hold standing OAuth grants into CRM, email, and storage. A stolen Zapier session lets an attacker build a workflow that exfiltrates on a schedule, from a vendor’s trusted IP space. No exploit needed; the integration is the persistence.
  • API keys are money, capacity, and cover. Keys lifted alongside everything else get billed to the victim or resold. Underground vendors sell discounted access to Claude, Gemini, and Cursor accounts with money-back guarantees — the retail layer of the LLMjacking economy Pillar Security mapped in Operation Bizarre Bazaar and the inference-theft campaigns we have tracked since.

Where the exposure concentrates

Technology and internet-services firms are the largest group at 144 companies and 40% of all records — and those firms hold data for many downstream clients, so the blast radius extends past their own perimeters. Industrials, financial services, retail, healthcare, and energy all appear in force. Slice by AI type rather than sector and the risk profile shifts: LLM-platform exposure is near-universal, highest in energy at 93% of affected companies, while agent and automation exposure — the kind that carries an employee’s authority into other systems — concentrates in healthcare, financial services, and technology.

Step back and the economics are bleak in their simplicity. None of this needs an autonomous agent swarm. One employee, one unmanaged laptop, one saved ChatGPT password, and one commodity infostealer that has been on sale in Telegram channels since 2022 is enough. Compare that with the lone-attacker agentic cloud compromises we covered in July: the low end of AI-era intrusion is not agentic at all — it is credential theft against accounts that happen to be AI.

What to do

  • Treat a stealer-log hit as an endpoint incident, not a password reset. If an employee appears in a stealer log, assume a live session is replayable right now. Hunt the device, revoke sessions and tokens, then rotate — in that order.
  • Put every AI platform behind SSO with short-lived sessions. OAuth 2.0/OIDC with refresh-token rotation shrinks the window in which a stolen cookie is saleable. Note the limits honestly: SSO removes the saved password, not the live session cookie, and does nothing for accounts opened before the policy existed.
  • Scope, cap, and rotate API keys — and alert on the LLMjacking fingerprint. Usage from unfamiliar ASNs or at odd hours is the classic signal. Bill shock is a detection source; treat it like one.
  • Monitor for session-token reuse. A session that changes country or device fingerprint mid-life is a replayed session. Build that rule before you need it.
  • Find the shadow accounts first. You cannot rotate what you do not know exists. Start by checking which of your domains already appear in stealer logs across the 40-plus AI platforms SOCRadar tracks — then bring the stragglers under SSO.

Our verification was source-led with a stated caveat. We read the full BleepingComputer writeup of SOCRadar’s AI Identity Exposure Report (published 28 September 2026) and cross-checked every figure cited above — the million-plus records, 80,000-plus domains, the 482-enterprise subset, the 5,434 records tied to 1,500 addresses, the 295-in-90-days recency, the 358-of-482 ChatGPT share, and the sector splits — against an independent second writeup that reproduces the same numbers. We did not independently audit SOCRadar’s stealer-log dataset, and readers should weigh the findings accordingly: the BleepingComputer piece is labelled as sponsored and written by SOCRadar itself, i.e. vendor research with a lead-generation tool attached. The Anthropic August response (sign-outs, payment-method wipes, refunds) is cited as reported by BleepingComputer, not as independently confirmed by us. We did not test exploitation against any account or session.

Sources: