AI Login Breach Affects 80,000+ Organizations: Understanding Shadow AI and LLMjacking

www.news4hackers.com-ai-login-breach-affects-80-000-organizations-understanding-shadow-ai-and-llmjacking-ai-login-breach-affects-80-000-organizations-understanding-shadow-ai-and-llmjacking

80,000 Organizations Exposed to AI Credential Theft: Insights from AI Identity Exposure Report

The Summer of 2026: A Critical Turning Point in Cybersecurity

The summer of 2026 marked a critical turning point in cybersecurity as enterprises grappled with a novel threat: the compromise of AI login credentials. In late August, Anthropic addressed a surge in session hijacking incidents linked to infostealer malware by forcibly logging users out, removing stored payment information, and issuing refunds for unauthorized transactions. This response highlighted the growing urgency of securing AI-driven identities.

Key Findings from the AI Identity Exposure Report

SOCRadar’s AI Identity Exposure Report delved into the broader implications, analyzing how stolen AI credentials from corporate environments are being exploited in underground markets. The study examined over one million infostealer records tied to AI services across 80,000+ corporate domains, narrowing the focus to 482 large enterprises. These organizations, spanning 36 countries and eight industries, included 68% that are valued at over $1 billion.

Overview of the Report

The research aimed to determine the origin of compromised credentials and the potential risks posed to enterprises. Among the findings, 5,434 records linked to 1,500 unique corporate addresses were identified, with 295 of the 482 companies appearing in the last 90 days. ChatGPT dominated the dataset, accounting for 358 of the 482 companies analyzed, representing 90% of all records in the study.

Platform-Specific Exposure

Other platforms such as Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs showed significantly lower exposure. The report noted a stark absence of Claude and Gemini in the top ranks, attributing this to their smaller corporate adoption rates. Researchers emphasized that this disparity reflects user behavior rather than inherent security flaws, pointing to ChatGPT’s early market dominance and the prevalence of personal device usage for work-related AI interactions.

Risks of Stolen AI Credentials

The risks associated with stolen AI credentials extend beyond traditional password breaches. Unlike conventional credentials, which typically grant access to a single application, a compromised AI account provides access to multiple critical functions: a searchable archive of interactions, an execution environment for code, a billable resource, and a digital identity.

Technical Exploitation Methods

Attackers can exploit session cookies to bypass multi-factor authentication, enabling unauthorized access without requiring passwords. Additionally, AI platforms often hold OAuth grants that allow automation tools like Zapier to interact with internal systems, creating pathways for data exfiltration.

Sector-Specific Vulnerabilities

The report highlighted sector-specific vulnerabilities. Technology and internet services firms accounted for 144 companies and 40% of all records, underscoring their role as custodians of sensitive data for downstream clients. Other sectors, including industrials, financial services, retail, healthcare, and energy, also showed significant exposure.

Industry-Specific Threats

Energy companies faced the highest prevalence of LLM-platform compromises, with 93% of affected organizations impacted. Meanwhile, healthcare, financial services, and technology sectors were most vulnerable to agent and automation-based attacks, which leverage employee credentials to execute workflows across interconnected systems.

Monetization of Stolen AI Credentials

The threat landscape is further complicated by the monetization of stolen AI credentials. Underground marketplaces offer discounted access to platforms like Claude, Gemini, and Cursor, often with guarantees of refunds. API keys and session tokens are particularly valuable, as they can be reused to generate revenue or resold.

Threat Actors and Tools

The report noted that a single unmanaged device infected with a commodity infostealer—available on Telegram since 2022—could suffice to compromise an organization’s AI infrastructure.

Mitigation Strategies for Enterprises

To mitigate these risks, the report recommends integrating AI platforms into enterprise security frameworks alongside identity providers and code repositories. Key strategies include enforcing single sign-on (SSO) with short-lived sessions using OAuth 2.0 or OIDC, rotating refresh tokens to limit the lifespan of stolen credentials, and monitoring API key usage for anomalies such as unexpected geographic locations or irregular activity patterns.

Proactive Security Measures

Organizations are also advised to treat any employee appearing in infostealer logs as an incident, prioritizing the discovery of shadow accounts that may predate security policies. The findings align with Anthropic’s response to its own incident, which involved invalidating compromised sessions, removing abused payment methods, and proactively notifying affected users.

Conclusion and Future Outlook

The report concludes that the exposure of AI credentials is not a matter of if, but when, and that enterprises must treat these identities with the same rigor as traditional access points. As AI adoption continues to expand, the security community must adapt to protect these increasingly valuable assets.

“The report noted a stark absence of Claude and Gemini in the top ranks, attributing this to their smaller corporate adoption rates. Researchers emphasized that this disparity reflects user behavior rather than inherent security flaws, pointing to ChatGPT’s early market dominance and the prevalence of personal device usage for work-related AI interactions.”


Blog Image

About Author

en_USEnglish