Cybercriminals Exploit Infostealer Logs to Bypass MFA with Stolen AI Tokens

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybercriminals are increasingly exploiting information stealer logs to hijack artificial intelligence (AI) user accounts, creating “stolen keys” that provide unauthorized access to tools from major model providers like Google and Anthropic. According to a report by The Hacker News, these attacks utilize information stealers such as Lumma Stealer and Vidar, which are designed to harvest a variety of sensitive data, including credentials, session tokens, and API keys.

Once the data is compromised, threat actors sell access to these logs on underground forums, facilitating follow-on attacks. Jeremy Kirk, director of threat intelligence at Okta, noted that “session tokens and API keys are sought specifically by threat actors because it is often possible to replay those secrets and bypass credential-based authentication.” This method allows attackers to effectively log into AI services without the need for traditional login credentials.

In a recent analysis, Okta examined a 7 GB infostealer dump released on a Telegram channel, which contained data from 5,871 infected machines across 162 countries. Among the findings were thousands of unexpired authentication tokens for services like Google, Microsoft, and Anthropic. Of the 44,791 unique JSON web tokens (JWTs) identified, 555 were likely associated with AI service authentication.

Worryingly, 17.7% of the JWTs contained plaintext personally identifiable information (PII), such as names and email addresses, which could be exploited for social engineering or phishing attacks. Okta emphasized the importance of securing access to AI systems and monitoring for session token reuse, as well as implementing OAuth 2.0 flows with short-lived tokens to mitigate risks associated with stolen credentials.

The rise in AI adoption within enterprise environments has led to a diversification of cybercriminal monetization strategies, with new black market sites emerging for purchasing stolen token bundles. As the demand for AI-related accounts grows, so does the need for robust security measures to protect sensitive information.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Pentagon plans to adjust FY27 budget priorities amid funding uncertainty

WASHINGTON — The Pentagon is preparing to adjust its budget priorities for fiscal year 2027 (FY27) in response to potential funding shortfalls, as indicated...

Clearview AI Develops Tool for Law Enforcement to Access Online Activity Profiles

Clearview AI is developing a new tool called InquiryIQ that enables law enforcement agencies to access detailed profiles of individuals based on their online...

Microsoft Launches Cloud Web Applications Threat Matrix to Enhance Security Against Evolving Cyber Threats

Microsoft has introduced a new framework aimed at enhancing security for cloud-hosted web applications and serverless platforms. The Cloud Web Applications Threat Matrix aligns...

Sophos to Present AI-Native Cybersecurity Solutions at GISEC 2026 in Dubai

Sophos, a prominent player in the global cybersecurity arena, is set to showcase its innovative AI-native cybersecurity solutions at GISEC Global 2026, taking place...