Technology

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

Bleeping Computer September 28, 2026 3 views

Advertisement

Credentials and active sessions for artificial intelligence tools linked to over 80,000 corporate domains have been exposed through infostealer logs, according to a new analysis by cybersecurity firm SOCRadar. The discovery highlights a growing threat landscape where stolen AI logins are being traded, creating significant risks for organizations that have adopted these technologies without adequate security controls.

The exposure stems from "Shadow AI," a term used to describe the unauthorized or unmonitored use of AI services within an organization. Because these tools are often accessed through personal accounts or lack centralized identity management, their credentials are particularly vulnerable to malware that harvests browser data and session tokens. Once compromised, these credentials allow attackers to access sensitive corporate data and ongoing conversations held within the AI platforms.

SOCArad's examination of the black market reveals a burgeoning trade in stolen AI logins, with threat actors actively seeking out credentials for popular large language models. This illicit market underscores a shift in cybercrime tactics, moving beyond traditional data theft to target the operational integrity of AI-driven workflows. The stolen sessions can be used to impersonate employees, extract proprietary information, or manipulate AI outputs for malicious purposes.

The report identifies a specific attack vector known as "LLMjacking," where attackers hijack active AI sessions to inject malicious prompts or alter the context of interactions. This technique allows adversaries to bypass standard security checks by leveraging the trusted status of the compromised user session. Consequently, the integrity of AI-generated content and the confidentiality of user inputs are severely compromised, posing a direct threat to business operations and data privacy.

Organizations are urged to audit their AI usage to identify any unapproved tools in circulation. Implementing robust identity and access management solutions, along with monitoring for anomalous AI activity, is critical to mitigating these risks. As the adoption of AI continues to accelerate, securing the credentials and sessions associated with these tools has become a paramount concern for corporate security teams.

<small>Source: Bleeping Computer — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement