Skip to main content
The Wire
CyberNews by Zentrya One
Malware

Infostealer Logs Reveal Stolen AI Session Tokens Capable of Bypassing MFA

Cybercriminals are increasingly targeting artificial intelligence accounts by stealing browser session tokens and API credentials from infected devices. These stolen artifacts may allow attackers to access AI services without entering a username, password, or multi-factor authentication (MFA) code.

An analysis of a large infostealer dataset revealed thousands of authentication artifacts linked to major technology and AI platforms. The findings highlight the growing risk of:

  • Unauthorized access to AI accounts
  • Theft of sensitive conversations and business data
  • Abuse of cloud and AI computing resources
  • Fraudulent API usage
  • Account resale in underground marketplaces
  • Follow-on phishing and social-engineering attacks

Infostealer Dataset Details

Okta’s threat intelligence team analyzed a 7 GB infostealer dump published on Telegram on August 2, 2026.

The dataset reportedly contained information collected from:

  • 5,871 compromised machines
  • 162 countries
  • Multiple technology, cloud, productivity, and AI platforms

Types of Data Found

The stolen information included:

  • User credentials
  • Browser session data
  • Authentication tokens
  • API keys
  • JSON Web Tokens (JWTs)
  • JSON Web Encryption (JWE) structures
  • Personally identifiable information
  • Other sensitive browser artifacts

AI and Technology Platforms Affected

The dataset contained tokens associated with several major services, including:

  • Google
  • Microsoft
  • Anthropic
  • Amazon
  • Notion
  • Character.AI
  • Cursor
  • Poe
  • Gamma
  • Pika AI

Key Findings at a Glance

Finding Reported Figure
Size of infostealer dump 7 GB
Compromised machines 5,871
Countries represented 162
Unique JWTs identified 44,791
JWTs linked to AI services 555
JWE structures identified 2,937
Valid JWTs and JWEs at publication 1,843
JWTs containing personal information Approximately 17.7%
Active AI-related API keys discovered 24

How Stolen Session Tokens Can Bypass MFA

A valid browser session token can act as proof that a user has already completed authentication. If an attacker obtains and reuses that token, the target service may recognize the attacker as an already-authenticated user.

In some cases, the attacker may not need to provide:

  • A username
  • A password
  • An MFA code
  • A security key
  • A biometric verification

Why This Creates a Security Challenge

MFA is highly effective at preventing unauthorized access through stolen passwords. However, MFA may not stop an attacker who has already obtained a valid session token.

The attack sequence may look like this:

  1. A victim’s device becomes infected with an infostealer.
  2. The malware extracts browser cookies or session tokens.
  3. The attacker obtains the stolen data.
  4. The attacker loads the token into a browser or automation tool.
  5. The target service accepts the token as an existing authenticated session.
  6. The attacker accesses the account without completing a new MFA challenge.

JWT and JWE Findings

Researchers identified 44,791 unique JSON Web Tokens (JWTs) in the dataset. Of these, 555 appeared to be associated with AI-related authentication.

The analysis also uncovered 2,937 JSON Web Encryption (JWE) structures containing encrypted authentication information. Many of these were reportedly associated with OpenAI services using NextAuth.js.

Encryption Does Not Always Prevent Replay

Encrypted tokens may be difficult to inspect without the appropriate cryptographic keys. However, encryption alone does not necessarily prevent token replay.

If a token is:

  • Still valid
  • Accepted by the target service
  • Not bound to a specific device
  • Not restricted by network or location controls

An attacker may potentially reuse it from another environment.

At the time the dump was published, researchers identified 1,843 JWTs and JWEs that were still valid.

Privacy Risks from Exposed Tokens

The dataset also created significant privacy concerns. Approximately 17.7% of the identified JWTs reportedly contained personally identifiable information (PII).

This information included:

  • Names
  • Telephone numbers
  • Email addresses

Attackers could use this information to:

  • Identify victims
  • Link individuals to specific online services
  • Create convincing phishing messages
  • Conduct social-engineering campaigns
  • Target employees or customers
  • Support identity-related fraud

Active AI API Keys Discovered

The threat extends beyond browser session authentication.

An analysis conducted with TruffleHog uncovered 24 active API keys associated with four AI-related services:

  • Google Gemini
  • OpenAI
  • Groq
  • OpenRouter

Potential Abuse of Stolen API Keys

Attackers may use compromised API keys to:

  • Access AI models
  • Generate unauthorized content
  • Consume paid computing resources
  • Run automated workloads
  • Conduct malicious activity
  • Resell access to other criminals
  • Use the victim’s account for large-scale operations

LLMjacking: Turning AI Resources into Criminal Infrastructure

The unauthorized use of stolen AI accounts and API keys is commonly referred to as LLMjacking.

The concept is similar to cryptojacking. Instead of secretly using a victim’s computing resources to mine cryptocurrency, attackers use the victim’s AI accounts or cloud infrastructure to run large language model workloads.

Consequences of LLMjacking

Organizations may experience:

  • Unexpected AI service charges
  • Exhausted API quotas
  • Reduced service availability
  • Increased cloud infrastructure costs
  • Exposure of proprietary prompts or data
  • Abuse of corporate accounts
  • Reputational damage
  • Potential regulatory concerns

Growing Underground Demand for AI Credentials

The increasing popularity and cost of advanced AI services are contributing to a growing market for stolen AI credentials.

Cybercrime communities are reportedly advertising access to services such as:

  • ChatGPT
  • Claude
  • Gemini
  • AI coding assistants
  • Autonomous development platforms
  • Premium AI model accounts
  • Cloud-based AI environments

Stolen credentials may be sold individually, bundled with other account data, or offered as part of broader access to compromised systems.

Tools Used to Reuse Stolen Authentication Data

Threat actors are also using specialized tools to load stolen browser data and imitate legitimate user sessions.

These tools may include:

  • Anti-detect browsers
  • Browser profile loaders
  • Session-cookie management tools
  • Automation frameworks
  • Credential replay utilities

Attackers may use these technologies to make stolen sessions appear more legitimate and evade controls based on:

  • Device identity
  • IP address
  • Browser characteristics
  • Geographic location
  • User-agent information
  • Behavioral patterns

Limitations of Token Replay

Token replay is not guaranteed to succeed in every environment. Several security controls can reduce the likelihood that a stolen token will work.

Controls That Can Limit Replay

Organizations can reduce token abuse through:

  • IP allowlisting
  • Device-bound authentication
  • Short-lived sessions
  • Frequent token rotation
  • Session revocation
  • Network access restrictions
  • Behavioral monitoring
  • Risk-based authentication
  • Endpoint detection and response

Device-Bound Session Credentials

Google has introduced Device Bound Session Credentials (DBSC) support in Chrome.

This technology is designed to cryptographically associate an authentication session with a specific device. As a result, a stolen session credential may be significantly harder to reuse from another system.

Device-bound sessions can help reduce the effectiveness of attacks involving:

  • Stolen browser cookies
  • Replayed session tokens
  • Credential theft from infected endpoints
  • Unauthorized access from unfamiliar devices

Broader Enterprise Risk

The threat is particularly important for organizations using AI across:

  • Software development
  • Security operations
  • Research
  • Customer support
  • Business analysis
  • Data processing
  • Cloud infrastructure
  • Product development

AI accounts may contain or provide access to:

  • Sensitive conversations
  • Proprietary prompts
  • Internal business information
  • Source code
  • Development environments
  • AI models
  • Customer data
  • Cloud computing resources

Additional Threat Intelligence Observations

Google’s threat intelligence researchers have observed increasing demand for AI accounts within cybercrime communities.

Criminal marketplaces are reportedly showing greater interest in:

  • Premium AI accounts
  • AI model access
  • Autonomous coding platforms
  • Cloud-based AI environments
  • Accounts with high usage limits
  • Credentials linked to enterprise services

Mandiant Incident Involving Cloud Resources

In one incident investigated by Google’s Mandiant team, attackers obtained an exposed GitHub Personal Access Token.

The attackers then used the access to:

  1. Deploy unauthorized AI infrastructure.
  2. Consume high-performance cloud computing resources.
  3. Generate costs for the affected organization.
  4. Use the compromised environment for unauthorized activity.

This incident demonstrates how a stolen development credential can become a gateway to AI and cloud resource abuse.

Recommended Security Measures

Organizations should treat AI authentication tokens and API keys as privileged credentials.

Identity and Access Controls

Security teams should:

  • Enforce phishing-resistant authentication.
  • Use device-bound sessions where available.
  • Apply least-privilege access policies.
  • Restrict access to approved networks and devices.
  • Require reauthentication for sensitive actions.
  • Disable unused accounts and API credentials.
  • Separate personal and enterprise AI accounts.

Token and API Key Management

Organizations should:

  • Use short-lived tokens whenever possible.
  • Rotate API keys regularly.
  • Revoke exposed credentials immediately.
  • Monitor for token reuse from unfamiliar locations.
  • Avoid storing secrets in source code or browser-accessible files.
  • Use centralized secrets-management platforms.
  • Apply strict permissions to AI APIs.
  • Set usage limits and spending alerts.

Endpoint Protection

Security teams should deploy:

  • Endpoint detection and response tools
  • Browser protection controls
  • Infostealer detection
  • Credential-theft monitoring
  • Application allowlisting
  • Security patches and updates
  • Malware scanning
  • Browser extension controls

Monitoring and Detection

Organizations should monitor for:

  • Authentication from unusual countries
  • Sudden changes in device fingerprints
  • Token reuse across multiple locations
  • Unusual API consumption
  • Unexpected AI model activity
  • Rapid increases in cloud costs
  • New API keys or service accounts
  • Access outside normal working hours
  • Large-scale prompt or data extraction
  • Repeated failed and successful authentication attempts

Incident Response Priorities

If an AI token or API key is suspected of being compromised, organizations should:

  1. Revoke the affected token or key.
  2. Terminate active sessions.
  3. Reset associated credentials.
  4. Review recent account activity.
  5. Inspect API usage and cloud billing.
  6. Search endpoints for infostealer malware.
  7. Investigate related browser and device activity.
  8. Check for unauthorized infrastructure.
  9. Review source-code repositories for exposed secrets.
  10. Notify affected users and stakeholders when necessary.

The Authentication Lesson

The findings highlight an important limitation of modern authentication: successfully authenticating a user is only one part of the security process.

If an attacker steals the session credential created after authentication, they may be able to bypass the authentication process entirely.

MFA remains an important security control, but it should be supported by:

  • Device-bound sessions
  • Strong endpoint security
  • Token monitoring
  • Rapid credential revocation
  • Network restrictions
  • Least-privilege access
  • Continuous authentication analysis

Conclusion

As AI services become more deeply integrated into enterprise environments, stolen AI identities are becoming increasingly valuable to cybercriminals.

Compromised session tokens and API keys can provide access to:

  • AI accounts
  • Sensitive conversations
  • Proprietary prompts
  • Business data
  • Development platforms
  • Cloud infrastructure
  • Expensive computing resources

Organizations must protect AI tokens and API keys with the same level of care applied to passwords, privileged accounts, and other high-value credentials.

The security of an AI account does not end when the user completes MFA. Protecting the session that follows authentication is equally important.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

critical Malware

Russian State-Sponsored Hackers Used Claude to Rebuild Malware After Detection

A Russian state-linked cyber-espionage operation has used Anthropic's Claude AI to create an automated malware-evasion workflow capable of detecting when its malicious tools were identified by security products and then modifying and rebuilding those tools to bypass the detections.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.