The SOCRadar AI Identity Exposure Report, published in late September 2026, analyzed over one million infostealer records tied to AI services across more than 80,000 corporate domains. From this set, researchers identified 482 major established enterprises and found 5,434 stealer-log records linked to 1,500 distinct corporate email addresses. Of those 482 companies, 295 appeared in the last 90 days.
ChatGPT dominates the dataset, with 358 of the 482 companies having at least one stolen employee credential or session. These companies account for roughly 90% of all records in the study. Other platforms such as Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs appear far less frequently. Notably, Claude and Gemini are absent from the top ranks.
The report notes that Anthropic last month responded to a similar threat of infostealer-driven hijacking of Claude sessions by signing users out, wiping saved payment methods, and refunding unauthorized charges. Researchers attribute ChatGPT's dominance to its first-mover advantage, suggesting that many employees have signed up with work emails on personal devices, making them prime targets for infostealers. As adoption of other AI assistants catches up, they expect the distribution to even out.
SOCRadar warns that a stolen AI login is more dangerous than a traditional password, as it can grant access to sensitive workflows, proprietary data, and paid usage. The report emphasizes that exposure follows user adoption, and for security teams, the risk lies wherever unmanaged usage occurs.