As reported by BleepingComputer, SOCRadar's AI Identity Exposure Report has quantified what many security teams suspected but few had measured: stolen AI logins are now a commodity. With over one million infostealer records tied to AI services across 80,000-plus corporate domains — and 68% of the 482 confirmed enterprises being billion-dollar organizations — this is not a fringe problem. It is a structural exposure created by the collision of shadow AI adoption and industrial-scale credential theft.
The core insight from this data is not that any particular AI vendor is insecure. ChatGPT's dominance in the stolen-credential dataset is a function of its first-mover adoption advantage, not a vulnerability in OpenAI's platform. The exposure follows the users — and the users are everywhere your acceptable-use policy doesn't reach.
Why a Stolen AI Session Is a Different Threat Class
Traditional credential theft typically grants access to one application with a bounded blast radius. A stolen AI session token is categorically worse because it simultaneously exposes:
Anthropic's late-August response to Claude session hijacking — force-signing users out, wiping payment methods, and refunding unauthorized charges — demonstrates the operational disruption this causes even when a vendor acts responsibly. But vendor-side response is reactive by definition. The damage to exposed conversation history is already done by the time a session is invalidated.
The Developer Tool Exposure Is Underappreciated
While ChatGPT dominates the dataset, the presence of Hugging Face, Replit, and Lovable in the logs is arguably more concerning for security-conscious organizations. These platforms handle source code, model artifacts, and deployment configurations. A stolen Hugging Face session can expose private model repositories, datasets, and API tokens. A compromised Replit session grants access to development environments that may contain secrets, environment variables, and proprietary application logic.
Security teams that focus only on consumer chatbot risk are missing the developer-tool attack surface, which carries higher intellectual property value per compromised session.
What Defenders Should Do
Shield53 Recommendations
- Discover your shadow AI footprint immediately. Run domain-based exposure checks against infostealer datasets. SOCRadar offers a free domain lookup; commercial threat intelligence platforms like Recorded Future and Mandiant also track stealer logs. If your domain appears, assume compromise and trigger incident response.
- Deploy SSO and conditional access for sanctioned AI tools. If employees are going to use AI platforms — and they are — route them through enterprise plans with SAML SSO, MFA enforcement, and session lifetime policies. Personal accounts provisioned with work emails are the primary exposure vector.
- Treat AI session tokens as sensitive credentials in EDR/DLP policies. Browser-stored tokens for AI platforms should be flagged by endpoint detection. Consider blocking personal-account logins on managed devices for high-risk AI services.
- Hunt for infostealer infections. The stolen AI logins in this dataset originated from infostealer malware on employee endpoints — often personal devices used for work. Deploy or verify EDR coverage, monitor for known stealer families (Lumma, Raccoon, RedLine, Vidar), and require device compliance checks for SaaS access.
- Build an AI acceptable-use policy that acknowledges reality. Banning AI tools drives more shadow usage, not less. Provide sanctioned channels, document what data is prohibited from being submitted, and train employees on credential hygiene for AI platforms specifically.
- Audit connected integrations. Review which third-party tools (Zapier, Notion, code platforms) are linked to corporate AI accounts. Each integration is an additional access path if a session is stolen.
The organizations most at risk are not those without AI policies — they are those whose policies assume employees will ask permission before adopting AI tools. By the time a policy is written, the credentials are already in a stealer log.
This dataset will grow. As Claude, Gemini, and other assistants gain enterprise adoption, the platform distribution in stealer logs will even out. The strategic move for security leaders is to stop thinking about AI tool governance as a vendor selection problem and start treating it as an identity and endpoint hygiene problem that happens to have a new application layer.