80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

A massive number of organizations have had their AI login credentials stolen, exposing sensitive corporate data to potential hackers. According to a recent report by SOCRadar, over 80,000 corporate domains have been compromised, with some of the biggest names in business among those affected.

The study focused on infostealer-driven hijacking of AI sessions, which allowed researchers to identify the companies whose employees’ credentials were being sold online. Of the 482 major enterprises analyzed, a staggering 68% are billion-dollar organizations across 36 countries and eight sectors. These companies include many Forbes-ranked firms, with a significant presence in North America.

The majority of stolen AI login credentials come from ChatGPT, which dominates the dataset with over 90% of all records. This is not surprising, given that ChatGPT has been widely adopted by employees on personal devices and company-issued laptops alike. However, this also raises concerns about the security of other popular AI platforms, such as Hugging Face and Replit.

The report’s findings have significant implications for Chief Information Security Officers (CISOs) and organizations as a whole. The exposure of AI login credentials is not just a technical issue, but a people problem. As adoption of AI platforms continues to grow, so too does the population of employees using them on personal devices outside of company policy. This creates an environment in which hackers can harvest sensitive corporate data with ease.

One of the most critical concerns surrounding stolen AI login credentials is their potential for misuse. Unlike traditional passwords, AI accounts are not just a single point of entry, but rather a combination of four things: a searchable archive, an execution engine, a billable resource, and an identity. This makes them far more valuable to hackers, who can inherit entire corporate archives, execute malicious code, and even steal sensitive data from internal systems.

The conversation history stored within these AI accounts is particularly vulnerable to exploitation. Employees often paste sensitive information into prompts, creating a digital repository of corporate memory that can be accessed by unauthorized parties. Furthermore, session cookies can bypass multi-factor authentication (MFA) protections, allowing hackers to maintain persistence on company networks even after rotating passwords.

The consequences of a stolen AI login credential are far-reaching and potentially devastating. Automation platforms, which often hold standing OAuth grants into CRM systems, email, and storage, can be compromised to build workflows that exfiltrate data on a schedule. API keys, which can be copied and resold online, represent a lucrative revenue stream for hackers.

The SOCRadar report highlights the need for organizations to reassess their security posture in light of this new threat landscape. CISOs must recognize that AI login credentials are not just another type of password to manage, but rather a critical component of an organization’s overall risk profile. By taking proactive steps to educate employees about secure AI usage and implementing robust authentication controls, companies can mitigate the risks associated with stolen AI login credentials.

Ultimately, this incident serves as a stark reminder that security is not just a technical problem, but also a people issue. As organizations continue to adopt new technologies, they must prioritize education, awareness, and policy development to ensure that employees understand the risks and consequences of using AI platforms outside of company guidelines.


Source: Bleeping Computer — 2026-09-28