80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

Major Cybersecurity Breach Exposed: Over 80,000 Organizations Affected by Stolen AI Logins

A massive cybersecurity breach has been uncovered, with over 80,000 organizations worldwide having their AI logins stolen. The breach, which was first reported in late August, has left many major corporations vulnerable to data theft and exploitation. At the center of this incident is a phenomenon known as LLMjacking, where attackers use stolen login credentials to gain access to sensitive corporate data.

The research behind this story, conducted by SOCRadar, identified 482 major established enterprises that had their AI logins compromised. Of these companies, 68% are billion-dollar organizations across 36 countries and eight sectors. The study found that chatbots, particularly ChatGPT, were the most commonly targeted platforms, with over 90% of all records in the study tied to this service.

The reason for this vulnerability lies in the way employees use AI services for work purposes. Many employees sign up for AI services using their corporate email addresses on personal devices, making it easier for infostealers to scrape login credentials. As a result, the exposure follows the users, and the users are often unaware of the risks associated with their behavior.

This breach is particularly concerning because an AI account is not just a simple credential; it’s a combination of four things: a searchable archive, an execution engine, a billable resource, and an identity. A stolen session hands over all these aspects without requiring a password prompt, making it a far more significant risk than a traditional stolen password.

The conversation history stored in AI accounts is also a major concern. Employees often paste sensitive information into prompts, creating a store of corporate memory that can be accessed by attackers. Once an attacker has access to this archive, they can replay the session and inherit all the associated data without touching internal systems.

Furthermore, session cookies are used to bypass MFA (Multi-Factor Authentication) and API keys can be lifted along with other credentials. This allows attackers to build workflows that exfiltrate data on a schedule from a vendor’s trusted IP space. In some cases, these API keys are even resold or billed to the victim.

The technology industry is particularly affected by this breach, with 144 companies and 40% of all records belonging to tech firms. However, other sectors such as industrials, financial services, retail, healthcare, and energy are also severely impacted.

To mitigate this risk, it’s essential for organizations to be aware of the exposure in their domain. SOCRadar offers a free tool that allows companies to check if their domain is affected and which AI platforms show stolen employee logins. By being proactive and taking steps to secure their AI accounts, businesses can minimize the damage caused by LLMjacking.

As the security industry continues to adapt to new threats, it’s clear that this breach serves as a wake-up call for organizations to reevaluate their cybersecurity policies and practices. The lesson here is not about choosing a “safer” AI assistant but rather understanding that exposure follows users, and users are often everywhere your policy isn’t. By taking immediate action, companies can prevent further exploitation and protect themselves from the devastating consequences of LLMjacking.


Source: Bleeping Computer — 2026-09-28