Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)
Infostealer-Stolen AI Service Logins Expose 80,000+ (TL-2026-2757), also tracked as Shadow AI to LLMjacking, is a high-severity malware campaign, first published 2026-09-28. It has no confirmed attribution, affects OpenAI ChatGPT / OpenAI accounts, maps to 10 MITRE ATT&CK techniques (T1078.004, T1204.002, T1496.004), and is covered by 9 detection rules and 11 indicators of compromise.
Key facts for TL-2026-2757
- Threat ID
- TL-2026-2757
- Also known as
- Shadow AI to LLMjacking, SOCRadar AI Identity Exposure Report 2026
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-28
- Last reviewed
- 2026-09-28
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, industrial, finance, retail, health, energy
- Target regions
- North America, Global
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Infostealer-Stolen AI Service Logins Expose 80,000+
Malware and tooling: AMOS, Acreed, Atomic Stealer, LummaC2, RedLine, Stealc, Vidar
SOCRadar's AI Identity Exposure Report 2026 maps over 1 million infostealer records tied to AI services across 80,000+ corporate domains, with ChatGPT/OpenAI accounts dominating. Stolen session cookies replay past MFA and stolen API keys enable LLMjacking; Anthropic separately reported infostealer-hijacked Claude sessions in late August 2026.
How Infostealer-Stolen AI Service Logins Expose 80,000+ works
SOCRadar (published as sponsored content on BleepingComputer on 2026-09-28) started from more than one million infostealer records tied to AI services across 80,000+ unique corporate domains, then narrowed the dataset to 482 major enterprises: about 68% billion-dollar organizations across 36 countries and 8 sectors, mostly in North America. In that subset SOCRadar found 5,434 stealer-log records tied to roughly 1,500 distinct corporate email addresses; 295 of the 482 companies surfaced within the last 90 days, and 358 of 482 had stolen ChatGPT/OpenAI credentials (about 90% of records). Technology/Internet services was the largest sector (144 companies, about 40% of records), with industrial, financial services, retail, healthcare and energy also exposed. Other AI/automation services seen in the logs include Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs; Claude and Gemini had minimal presence in this dataset.
The exposure is not a vulnerability in any AI vendor. It is generic infostealer malware on employee endpoints copying saved passwords, browser cookies and application credentials, which are then sold or used. SOCRadar argues stolen AI sessions are more dangerous than stolen passwords because they combine conversation history, replayable session cookies that bypass MFA, standing OAuth grants for agents and automation, and billable API keys. Session tokens and API keys are sought precisely because they can be replayed to bypass credential-based authentication. Keys pasted into notes apps or workspace settings pages are harvested with everything else, then billed to the victim or resold (LLMjacking). Stolen automation-platform sessions could enable scheduled data exfiltration from trusted vendor IP space. SOCRadar also reports underground vendors selling discounted AI account access with money-back guarantees.
A corroborating first-party incident: around 2026-08-30/31 Anthropic warned Claude users that a bad actor was using common infostealer malware to steal Claude login sessions. Families named by press coverage of the warning were Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows and Atomic Stealer (AMOS) on a small number of Macs. Attackers replayed stolen sessions to drain usage limits and prepaid credits (and potentially trigger auto-reload purchases) without needing a password or 2FA code. Anthropic signed out compromised sessions, removed saved payment methods, refunded unauthorized charges and emailed affected users. One affected user reportedly traced the infection to pirated game software; Anthropic stated the malware is not tied to Claude itself and typically arrives via unofficial downloads or malicious apps.
Caveats: the 80,000+ figure and all breakdowns are SOCRadar vendor statistics from sponsored content and are unverified independently. The SOCRadar article names no malware family, actor, CVE or IOC; the malware-family attribution comes only from coverage of the separate Anthropic Claude incident, and the two datasets should not be assumed to be the same campaign. The full SOCRadar report could not be retrieved (HTTP 403).
MITRE ATT&CK techniques used in TL-2026-2757
Initial Access
T1078.004 Valid Accounts: Cloud Accounts
Execution
T1204.002 User Execution: Malicious File
Impact
T1496.004 Resource Hijacking: Cloud Service Hijacking; T1657 Financial Theft
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Lateral Movement
T1550.004 Use Alternate Authentication Material: Web Session Cookie
Exfiltration
Affected products and versions in Infostealer-Stolen AI Service Logins Expose 80,000+
- OpenAI — ChatGPT / OpenAI accounts
Vulnerable versions: Accounts with credentials or sessions present in infostealer logs - Anthropic — Claude accounts
Vulnerable versions: Sessions stolen from infostealer-infected endpoints (Aug 2026)
Fixed in: Compromised sessions signed out by Anthropic - Zapier — Zapier accounts
Vulnerable versions: Accounts present in stealer logs - Notion — Notion accounts
Vulnerable versions: Accounts present in stealer logs - Hugging Face — Hugging Face accounts
Vulnerable versions: Accounts present in stealer logs - Replit — Replit accounts
Vulnerable versions: Accounts present in stealer logs - Lovable — Lovable accounts
Vulnerable versions: Accounts present in stealer logs - ElevenLabs — ElevenLabs accounts
Vulnerable versions: Accounts present in stealer logs
Remediation for Infostealer-Stolen AI Service Logins Expose 80,000+
Immediate actions
- Treat any employee appearing in a stealer log as an endpoint incident, not just a password reset: isolate, scan and remediate the host before restoring access
- Revoke all active sessions and OAuth grants for affected AI accounts and rotate any API keys stored in browsers, notes apps or workspace settings
- Review AI provider billing and usage for unexpected spend, and remove saved payment methods until endpoints are clean
Workarounds
- Where SSO is unavailable, require re-authentication for sensitive AI account actions and disable payment auto-reload
- Use SOCRadar's free AI Exposure Checker or equivalent breach-monitoring to identify exposed corporate domains
Longer-term hardening
- Enforce SSO (OAuth 2.0/OIDC) for AI services with short-lived sessions and refresh-token rotation
- Scope, cap and rotate API keys; alert on usage from unfamiliar ASNs or at odd hours
- Detect session-token reuse where a session changes country or device fingerprint mid-life
- Discover pre-existing shadow AI accounts before enforcing policy
- Block unofficial software downloads and pirated software on managed endpoints; deploy EDR with infostealer behavioral detection
Weaknesses (CWE) in Infostealer-Stolen AI Service Logins Expose 80,000+
CWE-522, CWE-384
Timeline of Infostealer-Stolen AI Service Logins Expose 80,000+
- Anthropic signs out compromised sessions, removes saved payment methods from affected accounts, refunds unauthorized charges and emails affected users.
- Anthropic warns some Claude users that a bad actor is using common infostealer malware to steal Claude login sessions and drain usage; BleepingComputer reports the warning.
- SecurityWeek and Help Net Security coverage names Vidar, Lumma, StealC, RedLine and Acreed (Windows) and Atomic Stealer (macOS) as the infostealer families involved.
- Malwarebytes publishes guidance: attackers consume usage allowances and prepaid credits and may trigger auto-reload; victims should scan devices before logging back in.
- BleepingComputer publishes the SOCRadar-sponsored article 'From Shadow AI to LLMjacking' summarizing the findings and defensive recommendations.
- SOCRadar publishes its AI Identity Exposure Report 2026: 1M+ infostealer records tied to AI services across 80,000+ corporate domains; 482 enterprises analyzed.
Sources cited for Infostealer-Stolen AI Service Logins Expose 80,000+
- 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking (BleepingComputer, sponsored by SOCRadar)
- SOCRadar AI Identity Exposure Report 2026
- New SOCRadar AI Identity Exposure Report Reveals 80,000+ Enterprises Had Employee AI Logins Stolen (The IT Nerd)
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage (BleepingComputer)
- Anthropic Warns Claude Users of Infostealer Malware Infections (SecurityWeek)
- Anthropic locks out Claude users after infostealers hijack login sessions (Help Net Security)
- Infostealers are hijacking Claude accounts at users' expense (Malwarebytes)
- Infostealers Are Hijacking Claude Sessions and Draining Subscriptions (Security Affairs)
More in malware
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
Detection coverage for TL-2026-2757
As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2757 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.