Identity
Infostealers now harvest AI sessions and API keys
A SOCRadar study found ChatGPT sessions in stealer logs at 358 of 482 large firms. Why a stolen AI cookie beats a password, and how to lock AI accounts down.
Infostealer malware has always grabbed whatever a browser stores: passwords, cookies, card numbers. AI accounts are now one of the things buyers look for in that haul. SOCRadar's AI Identity Exposure Report, published on September 28, matched more than one million infostealer records tied to AI services against over 80,000 corporate email domains. In a closer study of 482 large enterprises, a captured ChatGPT or OpenAI session turned up at 358 of them.
This matters now because the stolen item is usually a live session, which skips the password and the multi-factor authentication (MFA) prompt entirely, and because an employee's AI account often holds pasted source code, uploaded files and connections into email or storage. At the end of August, Anthropic had to sign out affected Claude users after stealers hijacked their sessions. If your staff use AI tools on personal sign-ups, you probably have exposure you cannot see.
All of the numbers in that graphic come from one vendor report. Security Affairs, BleepingComputer and Secureblink each reported the same figures, but none of them collected the data independently.
How it works
An infostealer is commodity malware, often bundled with pirated software or a fake installer. It runs once, copies the browser's saved logins, cookie database and autofill data plus any files that look like secrets, and uploads the bundle (a "log") to its operator. The malware families Anthropic named in its August incident are the usual ones: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer on a small number of Macs. One affected user traced the infection to a pirated game.
The cookie is the valuable part. When you sign in to ChatGPT or Claude, the service sets a session cookie that says "this browser has already passed login and MFA". An attacker who imports that cookie into their own browser arrives as you, with no password prompt and no MFA challenge, until the session expires or is revoked. Changing the password does not end it.
What sits behind that session is the reason buyers pay for it:
- Chat history and uploaded files. People paste code, contracts, customer records and plans into prompts, and the history is searchable.
- Connectors and automation grants. SOCRadar notes that AI and automation accounts such as Zapier hold standing OAuth grants into CRM, email and storage. OAuth is the protocol that lets one app act on your behalf in another, and the grant usually outlives the session that created it.
- API keys. A developer's laptop often has keys for OpenAI or Anthropic in environment files. Every request made with them is billed to the victim.
What attackers are doing
SOCRadar's 482 enterprises account for 5,434 stealer log records linked to 1,500 distinct corporate email addresses, and 68 percent of the firms are billion-dollar companies. ChatGPT dominates: the 358 firms with an OpenAI session carry roughly 90 percent of all records. Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs follow far behind. Claude and Gemini barely appear. SOCRadar puts that down to smaller corporate footprints and shadow AI use, and says it does not mean those accounts are harder to steal.
The resale market is open about it. Between July and September 2026, underground forums advertised Claude API keys, ChatGPT cookies from paid and Pro accounts, and Cursor sessions, some with money-back guarantees. Using stolen access to run AI models at someone else's expense is called LLMjacking. In one case CrowdStrike documented and Axios reported, an attacker holding a cloud identity with a long-term access key sent nearly 200,000 model API requests in a two-minute burst before throttling kicked in.
Anthropic's incident shows the consumer side. Stealers took Claude session cookies and the attackers used them to burn through victims' paid usage. Anthropic signed out the affected sessions, removed saved payment methods and refunded unauthorised charges, and warned that signing out does nothing about malware still on the machine.
Credential phishing runs alongside. In September, Cofense reported emails headed "Subscription Payment Required" that gave ChatGPT users 48 hours to update payment details. The button went through a notifications.googleapis.com redirect to a fake login page on nxcli.io subdomains, sent from support@9527db6e1a.nxcli.io. The real ChatGPT login lives on auth.openai.com.
What to do
- Move AI use onto accounts you control. ChatGPT Business and Enterprise let you verify your domain and enforce SAML or OIDC single sign-on (SSO), after which accounts on that domain can no longer use Google, Microsoft or password logins. Claude Enterprise's domain capture routes every sign-in with a company address into your organisation; it needs DNS verification, enforced SSO and JIT or SCIM provisioning first, and it cannot be undone, so plan it. Once sign-in goes through your identity provider, its session lifetime and conditional access rules apply.
- Be able to kill sessions quickly. For managed accounts, disabling the user in the identity provider and deprovisioning through SCIM removes access. For anything else, use the provider's sign out of all devices option, then revoke the OAuth grants the AI tool holds in Google Workspace or Microsoft Entra, since signing out does not touch them.
- Scope and rotate API keys. Give OpenAI keys per-project scope and set permissions to Restricted or Read only where a service does not need everything. In the Anthropic Console, split work into workspaces with their own spend and rate limits. Rotate any key that has lived on a developer laptop, and keep keys out of
.envfiles on endpoints where you can use a secrets manager instead. - Handle a stealer infection as a full incident. Re-image or fully clean the machine first, otherwise the next session gets stolen too. Then revoke every session the browser held, not only AI ones, and rotate every credential and key stored on it.
- Detect stealers on the endpoint. Alert when a process other than the browser reads browser cookie stores, such as Chrome's
User Data\Default\Network\Cookiesfile. Chrome 146 on Windows turned on Device Bound Session Credentials in April 2026, which ties cookies to a key in the TPM (the laptop's hardware security chip), but it only protects sites that implement it. - Check whether you are already exposed. Search stealer log feeds for your domains and filter for AI service URLs. Review usage per API key in the OpenAI and Anthropic consoles for spikes, odd hours or models your team does not use.
- Close the offboarding gap. Add AI tools, their API keys and their connector grants to the leaver checklist, so a departed employee's ChatGPT session or Cursor login does not keep working.
The wider lesson
Most identity programmes still count passwords and MFA coverage. Stealer logs show that the session is the credential that matters, and AI tools adopted outside IT are exactly where nobody can revoke one. An inventory of which AI services staff sign in to, and with which addresses, is the starting point for everything above.
Locking down sign-in, sessions and OAuth grants across SaaS and AI tools is part of our safeguarding and hardening work, and stealer detection and session revocation sit in security operations. If you want to know how exposed your organisation's AI accounts are, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Security Affairs, The IT Nerd, BleepingComputer, Secureblink, Axios, Help Net Security, BleepingComputer on Claude sessions, GBHackers, Help Net Security on the ChatGPT phishing, Help Net Security on DBSC, OpenAI Help Center, Claude Help Center.