Infostealers Harvest Corporate AI Sessions and API Keys, Exposing 482 Companies' AI Accounts
What Happened — Security‑research firm SOCRadar analyzed 90 days of stealer‑log data and identified 482 organizations with exposed AI‑service credentials. The majority (≈90 %) involved ChatGPT/OpenAI sessions, but the dump also contained active tokens for Zapier, Notion, Hugging Face, Replit, ElevenLabs and others. In many cases the credentials were still valid, meaning attackers could replay sessions or invoke APIs without needing the password again.
Why It Matters for Trust & Control Assurance
- The incident illustrates a control gap in session‑token lifecycle management – rotating passwords does not invalidate live tokens, leaving a persistent foothold.
- Continuous monitoring of credential usage and automated revocation of stale or anomalous tokens are core to an identity‑and‑access‑control assurance program.
- Verisq’s Access Controls capability provides real‑time token visibility, policy‑driven session termination, and audit‑ready evidence of remedial actions.
Who Is Affected
- Enterprises across technology, finance, consulting and other sectors that allow employees to use AI services with corporate credentials.
Recommended Actions
- Enforce MFA for all AI‑service logins and require corporate‑managed identities (e.g., SSO).
- Deploy automated token‑revocation workflows that invalidate sessions and API keys on credential change or anomalous activity.
- Implement continuous monitoring of AI‑service authentication logs for abnormal usage patterns.
- Establish clear policies governing personal‑device access to corporate AI accounts and enforce them with endpoint controls.
Source: SecurityAffairs article
Technical Notes
- Attack vector: credential‑stealing malware (infostealers) harvesting stored session cookies and API keys from browsers and local credential stores.
- Exposed assets: active session tokens, refresh tokens, API keys for OpenAI, Zapier, Notion, Hugging Face, Replit, ElevenLabs, etc.
- No public CVE; the risk stems from insecure credential handling and lack of token lifecycle controls.
Source: same article