Corporate secrets increasingly vanish through infected browser data rather than direct AI service breaches. SOCRadar analyzed over a million infostealer records in their recent report on AI identity exposure. Furthermore, researchers discovered more than 80,000 corporate domains in these logs. Consequently, the company selected 482 major enterprises for a detailed investigation.
The figure of 80,000 does not equal confirmed corporate network breaches. Instead, it represents domains linked to credentials and sessions captured in stealer logs. Within the sample of 482 companies, SOCRadar counted 5,434 compromised records. These records connected to approximately 1,500 professional email addresses. Moreover, 295 of these organizations appeared in these malicious logs within the last 90 days.
The Dominance of ChatGPT
ChatGPT and other OpenAI services dominated this detailed sample. Investigators found their credentials or sessions at 358 out of 482 companies. Consequently, records linked to OpenAI constituted nearly 90% of the dataset. SOCRadar attributes this overwhelming majority to massive adoption rates. It also points to the rise of shadow AI. This phenomenon occurs when employees create work accounts outside official corporate oversight.
How Infostealers Operate
An infostealer functions as a malicious software program. It extracts passwords, cookies, and session tokens from an infected device. A valid token confirms a previously successful login. Therefore, attackers often bypass passwords and multi-factor authentication entirely. Furthermore, simply changing a password does not always terminate a stolen active session.
For an AI account, the consequences extend far beyond mere password theft. Employees often upload source code, client details, or internal plans into chat interfaces. A stolen session can easily expose this entire conversation history. The report does not claim that data leaked in every single case. However, it vividly illustrates a severe corporate risk. Access to query histories transforms simple credential theft into a profound security crisis.
Escalating Corporate Risks
Accounts linked to other services via OAuth present even greater dangers. These represent pre-granted access permissions. Workflows in Zapier and similar platforms frequently access emails, cloud storage, or CRM systems. Thus, stealing an active session grants the attacker the AI interface itself. Crucially, it also grants all permissions previously assigned to that employee. These acute risks surfaced most frequently within the technology, finance, and healthcare sectors.
The Threat of LLMjacking
A distinct attack scenario involves API keys. Stealers can easily harvest a key from settings, notes, or developer files. Criminals then exploit this stolen premium access to the model. Alternatively, they might resell it on the dark web. Security experts call this lucrative scheme LLMjacking. Consequently, a company risks both its proprietary data and its entire computing budget. The legitimate key owner inevitably pays for the unauthorized queries.
Technology and internet companies suffered the most compromises in the detailed sample. This sector accounted for 144 organizations and roughly 40% of the dataset. In the energy sector, 93% of affected companies exhibited compromised large language model platforms. However, this specific sample consists solely of 482 large enterprises. Therefore, it does not reflect the global infection rate across all businesses.
Real-World Consequences
A remarkably similar mechanism recently affected Claude users. In late August, Anthropic officially warned that infostealer malware is hijacking Claude sessions to drain usage. The company subsequently deleted saved payment methods for affected users. Furthermore, they refunded charges deemed entirely unauthorized. The organization blamed ordinary stealers on infected computers rather than a fundamental vulnerability in Claude.
Mitigation Strategies
SOCRadar advises integrating AI services into overall identity management frameworks. Companies must enforce single sign-on and mandate remarkably short sessions. Administrators should strictly limit and frequently rotate API keys. They must also monitor for token reuse and anomalous network logins. If an employee appears in a stealer log, the company must assume device infection. Simply changing a password remains insufficient while the malware silently persists on the machine.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.