Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

80,000+ Organizations Exposed as AI Login Credentials Stolen by Infostealers

More than one million records from credential‑stealing malware contain AI service logins, affecting 80 000+ corporate domains and 482 large enterprises. The breach highlights the need for robust identity‑and‑access controls and continuous monitoring of AI‑related accounts for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
8 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

80,000+ Organizations Had AI Login Credentials Stolen – Infostealer‑Driven “LLMjacking”

What Happened — A new SOCRadar report, corroborated by Anthropic’s late‑August response, shows that more than one million records from credential‑stealing malware contain logins to AI services. The data span 80 000+ corporate domains, with 482 large enterprises (68 % billion‑dollar firms) represented. ChatGPT accounts dominate the exposure, but other platforms such as Hugging Face, Replit, Zapier and Notion also appear.

Why It Matters for Trust & Control Assurance

  • The incident exemplifies a failure to enforce consistent identity‑and‑access policies for AI tools that employees adopt on personal devices. Continuous control‑assurance programs must capture such shadow‑AI usage and verify credential hygiene.
  • Stolen AI sessions grant attackers a searchable knowledge base, execution engine, billing authority, and identity in one, expanding the attack surface far beyond a traditional password breach. Demonstrable evidence of credential‑management controls and real‑time monitoring is essential to defend against this vector.
  • Mapping this breach to the Access Control control objective (e.g., “manage, monitor, and revoke privileged and service accounts”) provides a single, framework‑agnostic trust signal that satisfies multiple standards (NIST CSF 2.0, ISO 27001, etc.).

Who Is Affected — Large enterprises across finance, technology, professional services, manufacturing, healthcare, retail, media, and other sectors that allow employees to sign up for AI services with corporate email addresses.

Recommended Actions

  • Inventory all AI‑related accounts (ChatGPT, Claude, Gemini, etc.) tied to corporate identities and classify them as privileged assets.
  • Enforce MFA, session timeout, and automated credential rotation for AI services; integrate these controls into your existing IAM platform.
  • Deploy continuous monitoring that flags anomalous AI‑login activity (new device, geographic shift, unusual billing).
  • Incorporate AI‑credential evidence into your audit readiness artifacts (access‑control logs, revocation records, policy attestations).

Technical Notes — The theft originates from widely deployed infostealer malware that harvests saved browser sessions, credential stores, and token files. No specific CVE is cited; the vector is “stolen credentials” via malicious software. Affected AI platforms include OpenAI (ChatGPT), Anthropic (Claude), Hugging Face, Replit, Zapier, Notion, Lovable, and ElevenLabs. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →