Stolen AI Logins: A New Frontier for Corporate Data Exposure
A recent report by **SOCRadar** reveals a surge in corporate AI account compromise, with over 80,000 corporate domains linked to infostealer records. These stolen AI logins, particularly for platforms like **ChatGPT**, present a far greater risk than traditional credential theft, offering attackers access to sensitive corporate data and the ability to bypass multi-factor authentication.

The security industry is grappling with a new threat: the stolen AI login. This past August, **Anthropic** responded to widespread infostealer-driven hijacking of **Claude** sessions by forcing sign-outs, wiping payment methods, and refunding unauthorized charges. This incident underscored the 'supply side' of the problem.
Now, **SOCRadar's AI Identity Exposure Report** delves into the 'demand side' β the enterprises whose employees' AI credentials are being actively sold on the dark web.
### The Scale of Exposure
**SOCRadar** analyzed over one million infostealer records tied to AI services across more than 80,000 corporate domains. The research focused on 482 major established enterprises, revealing a concerning trend:
* 68% of these organizations are billion-dollar entities across 36 countries and eight sectors, primarily concentrated in North America.
* The study identified 5,434 stealer-log records linked to 1,500 distinct corporate email addresses within these companies.
* Alarmingly, 295 of the 482 organizations surfaced in the last 90 days, indicating a rapid increase in compromise.
### ChatGPT Dominates Compromised Accounts
When broken down by platform, **ChatGPT** and **OpenAI** sessions overwhelmingly dominate the dataset. They account for 358 of the 482 companies and roughly 90% of all records in the study. Other platforms like **Zapier**, **Notion**, **Hugging Face**, **Replit**, **Lovable**, and **ElevenLabs** trail significantly.

Crucially, platforms like **Claude** and **Gemini** are notably absent from the top ranks. Researchers suggest this isn't due to superior security, but rather **ChatGPT's** first-mover advantage, leading to more employees signing up with work emails on personal devices. As other AI assistants gain traction, this distribution is expected to even out.
For Chief Information Security Officers (CISOs), the key takeaway is clear: exposure follows the users, extending beyond the reach of existing corporate policies.
### Why Stolen AI Logins Are More Dangerous
Unlike a traditional credential that unlocks a single application, a stolen AI account grants access to a powerful combination of resources:
* **Searchable Archive:** Employees frequently paste sensitive dataβsource code, customer records, contracts, unreleased plansβinto AI prompts. The stolen session provides an attacker with a complete history of this corporate memory.
* **Execution Engine:** AI platforms can act with the employee's authority. Stolen session cookies bypass multi-factor authentication (MFA), allowing attackers to maintain access even if the password is changed.
* **Billable Resource:** Compromised API keys, often found in notes or workspace settings, can be used for fraudulent billing or resold on the dark web for 'LLMjacking' operations.
* **Identity:** Automation platforms like **Zapier** often hold standing **OAuth** grants to CRM, email, and storage systems. A stolen **Zapier** session could enable an attacker to exfiltrate data from a trusted IP space.

### Widespread Industry Exposure
While technology and internet-services firms represent the largest group of affected companies (144 companies, 40% of records), the exposure is pervasive across all sectors.

Exposure to Large Language Model (LLM) platforms is near-universal, with the energy sector showing the highest percentage of affected companies at 93%. Exposure to agent and automation platforms, which carry significant authority into other systems, is concentrated in healthcare, financial services, and technology.

The report emphasizes that this widespread compromise doesn't require sophisticated attacks. A single employee, an unmanaged laptop, a saved **ChatGPT** password, and a common infostealer are often enough to facilitate a breach.
### Mitigating the Risk
The controls needed are not revolutionary, but their application to AI platforms is new. AI platforms must now be treated with the same criticality as identity providers and code repositories.
* **Implement SSO with Short-Lived Sessions:** Utilize **OAuth 2.0 / OIDC** with refresh-token rotation. This ensures stolen cookies expire quickly, limiting their utility. Remember, SSO doesn't address accounts created before policy implementation.
* **Scope, Cap, and Rotate API Keys:** Monitor for unusual API key usage, such as activity from unfamiliar Autonomous System Numbers (**ASNs**) or at odd hours, which can indicate LLMjacking.
* **Monitor for Session-Token Reuse:** Any session showing a sudden change in country or device fingerprint should be treated as replayed and immediately investigated as an endpoint incident, not just a password reset.
* **Discover Shadow Accounts:** Organizations cannot protect what they don't know exists. Start by identifying which corporate domains already appear in infostealer logs. **SOCRadar** offers a [free AI Identity Exposure tool](https://socradar.io/free-tools/ai-exposure-checker?utm_campaign=16179527-GatedContent_Dark-Web-Reports_Global_0725&utm_source=BleepingComputer&utm_medium=BleepingComputer&utm_term=AIExposure2026&utm_content=FormSubmissions) for this purpose.
**Anthropic's** proactive response to its own incidentβinvalidating sessions, stripping payment methods, and notifying affected usersβserves as a template for effective incident response in this evolving threat landscape.
[Read the complete report by **SOCRadar** for more in-depth analysis.](https://socradar.io/resources/report/ai-identity-exposure-report-2026.html?utm_campaign=16179527-GatedContent_Dark-Web-Reports_Global_0725&utm_source=SponsoredBlog&utm_medium=BleepingComputer&utm_term=AiIdentity2026&utm_content=FormSubmissions)