Over 80,000 organizations had AI credentials stolen in infostealer campaigns, report finds

SOCRadar analysis of 482 major enterprises reveals 68% are billion-dollar firms; ChatGPT sessions dominate stolen logs

By LineZotpaper
Published
Read Time2 min
A new report from SOCRadar has uncovered that more than 80,000 organizations had AI service credentials stolen by infostealer malware, with researchers narrowing their focus to 482 major enterprises to assess the scale of exposure. Of those, 68% are billion-dollar organizations across 36 countries, concentrated in North America, and many are Forbes-ranked. The findings come amid a broader rise in AI credential theft, including a recent incident where Anthropic responded to hijacked Claude sessions.

The SOCRadar AI Identity Exposure Report, published in late September 2026, analyzed over one million infostealer records tied to AI services across more than 80,000 corporate domains. From this set, researchers identified 482 major established enterprises and found 5,434 stealer-log records linked to 1,500 distinct corporate email addresses. Of those 482 companies, 295 appeared in the last 90 days.

ChatGPT dominates the dataset, with 358 of the 482 companies having at least one stolen employee credential or session. These companies account for roughly 90% of all records in the study. Other platforms such as Zapier, Notion, Hugging Face, Replit, Lovable, and ElevenLabs appear far less frequently. Notably, Claude and Gemini are absent from the top ranks.

The report notes that Anthropic last month responded to a similar threat of infostealer-driven hijacking of Claude sessions by signing users out, wiping saved payment methods, and refunding unauthorized charges. Researchers attribute ChatGPT's dominance to its first-mover advantage, suggesting that many employees have signed up with work emails on personal devices, making them prime targets for infostealers. As adoption of other AI assistants catches up, they expect the distribution to even out.

SOCRadar warns that a stolen AI login is more dangerous than a traditional password, as it can grant access to sensitive workflows, proprietary data, and paid usage. The report emphasizes that exposure follows user adoption, and for security teams, the risk lies wherever unmanaged usage occurs.

§

Analysis

Why This Matters

  • Stolen AI credentials can give attackers access to corporate AI workflows, proprietary data, and paid usage quotas, enabling fraud and data theft.
  • The widespread use of work emails on personal devices for AI services creates a shadow AI problem that bypasses corporate security controls.
  • As more employees adopt various AI assistants, the attack surface will expand, and the current dominance of ChatGPT may shift to other platforms.

Background

The report highlights the growing problem of shadow AI, where employees use AI services without official approval, often with personal accounts linked to work emails. Infostealer malware, which scrapes saved passwords and session cookies from browsers, has become a primary vector for harvesting these credentials. The recent incident at Anthropic, where Claude sessions were hijacked, shows that all AI platforms are vulnerable once they have sufficient corporate adoption.

Key Perspectives

Security Researchers (SOCRadar): They stress that the exposure follows user adoption, not platform security. They call for enterprises to monitor AI usage and implement policies to prevent shadow AI, and they note that ChatGPT's dominance may be temporary. Enterprises and CISOs: They face the challenge of securing AI usage that often occurs outside IT visibility. The report suggests that the solution is not choosing a safer assistant but managing the overall environment. Attackers: They are increasingly targeting AI sessions because a stolen AI login can provide access to customer data, proprietary code, and compute resources, potentially leading to LLMjacking (unauthorized use of AI models).

What to Watch

  • Whether other AI platforms, such as Claude and Gemini, see similar levels of credential theft as their corporate footprints grow.
  • How AI vendors respond with security measures, such as the forced logout and refund policy Anthropic implemented.
  • The adoption of enterprise-grade AI management tools to detect and block unauthorized AI usage.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.