Cybercriminals are increasingly exploiting information stealer logs to hijack artificial intelligence (AI) user accounts, creating “stolen keys” that provide unauthorized access to tools from major model providers like Google and Anthropic. According to a report by The Hacker News, these attacks utilize information stealers such as Lumma Stealer and Vidar, which are designed to harvest a variety of sensitive data, including credentials, session tokens, and API keys.
Once the data is compromised, threat actors sell access to these logs on underground forums, facilitating follow-on attacks. Jeremy Kirk, director of threat intelligence at Okta, noted that “session tokens and API keys are sought specifically by threat actors because it is often possible to replay those secrets and bypass credential-based authentication.” This method allows attackers to effectively log into AI services without the need for traditional login credentials.
In a recent analysis, Okta examined a 7 GB infostealer dump released on a Telegram channel, which contained data from 5,871 infected machines across 162 countries. Among the findings were thousands of unexpired authentication tokens for services like Google, Microsoft, and Anthropic. Of the 44,791 unique JSON web tokens (JWTs) identified, 555 were likely associated with AI service authentication.
Worryingly, 17.7% of the JWTs contained plaintext personally identifiable information (PII), such as names and email addresses, which could be exploited for social engineering or phishing attacks. Okta emphasized the importance of securing access to AI systems and monitoring for session token reuse, as well as implementing OAuth 2.0 flows with short-lived tokens to mitigate risks associated with stolen credentials.
The rise in AI adoption within enterprise environments has led to a diversification of cybercriminal monetization strategies, with new black market sites emerging for purchasing stolen token bundles. As the demand for AI-related accounts grows, so does the need for robust security measures to protect sensitive information.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



