Skip to content
Tech News
← Back to articles

SOCRadar finds AI login credentials stolen from 80,000+ organizations

read original get YubiKey 5C NFC Security Key → more articles
GoKawiil Brief

SOCRadar's AI Identity Exposure Report analyzed over one million infostealer records tied to AI services across more than 80,000 corporate domains, narrowing to 482 major enterprises. The study found 5,434 stealer-log records linked to 1,500 corporate email addresses, with 295 of the 482 companies appearing in stealer logs within the last 90 days, and ChatGPT/OpenAI accounts making up roughly 90% of all captured records.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The heavy concentration of ChatGPT credentials, with no Claude or Gemini logins ranking highly, suggests employees are signing up for AI tools with work emails on personal devices without IT oversight, a pattern researchers describe as a shadow-AI signal rather than evidence that OpenAI's security is weaker. This could indicate that as enterprises adopt other AI assistants, similar exposure will spread across platforms, raising broader questions about how organizations govern employee use of AI tools.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — Infostealer malware thrives on credentials that can be silently harvested and replayed, but a hardware security key like the YubiKey adds a phishing-resistant second factor that stolen passwords alone can't bypass. It's a practical way for anyone using AI tools like ChatGPT to lock down logins against exactly the kind of session-hijacking described in this report. Compact, durable, and works across major platforms supporting FIDO2/WebAuthn.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-28

Published there as: “80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.