By Interestana AI Editorial — AI-drafted, human-overseen. How we report
80,000+ Organizations Exposed by Stolen AI Logins
Infostealer logs have exposed AI account credentials and active sessions linked to over 80,000 corporate domains, according to a recent examination by SOCRadar. This widespread compromise creates significant security risks, including the potential for stolen sensitive conversations and the malicious exploitation of large language models, a practice termed LLMjacking. The analysis highlights a burgeoning illicit market for these stolen AI login credentials, underscoring the escalating threat landscape surrounding artificial intelligence adoption within organizations.
The compromised data includes session tokens, which allow unauthorized access to AI platforms without requiring traditional username and password authentication. This method of access is particularly concerning as it bypasses multi-factor authentication (MFA) and provides attackers with immediate, persistent access to AI tools and the data processed by them. SOCRadar's findings indicate that the stolen credentials are being traded on dark web forums, suggesting a structured and active underground economy focused on exploiting AI vulnerabilities. The sheer volume of affected organizations, exceeding 80,000, points to a systemic issue in how AI access is secured and managed across various industries.
LLMjacking, a primary concern arising from these breaches, involves attackers hijacking an organization's access to AI models to perform unauthorized actions. This could include generating malicious content, conducting phishing attacks, or even training models with stolen proprietary data. The exposure of sensitive conversations is another critical risk, potentially leading to intellectual property theft, reputational damage, and regulatory non-compliance. The report emphasizes that many organizations may be unaware of their exposure, as the compromised accounts could be tied to "shadow AI" – AI tools adopted by employees without official IT department approval or oversight. This lack of centralized control makes it challenging for security teams to identify and mitigate risks effectively.
SOCRadar's analysis suggests that the threat actors are leveraging infostealer malware to harvest these credentials. This malware, often disguised as legitimate software, silently collects sensitive information from infected devices, including browser cookies and session tokens related to AI services. The scale of the breach indicates that attackers are systematically targeting AI platforms, recognizing their increasing importance and the valuable data they handle. Organizations are urged to conduct thorough audits of their AI usage, implement robust access controls, and educate employees about the risks associated with unapproved AI tools to safeguard against such sophisticated attacks.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.