Anthropic and ChatGPT: 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

Anthropic and ChatGPT: 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

Stolen AI Logins Expose Corporate Data in Growing Infostealer Threat

In August 2026, Anthropic responded to a surge in infostealer-driven hijackings of its AI assistant, Claude, by forcibly signing out users, wiping saved payment methods, and refunding unauthorized charges. The incident highlighted a broader trend: cybercriminals are increasingly targeting AI service credentials, with corporate employees as the primary victims.

A recent SOCRadar AI Identity Exposure Report analyzed over 1 million infostealer records tied to AI services across 80,000+ corporate domains, narrowing the focus to 482 major enterprises 68% of which are billion-dollar organizations spanning 36 countries and eight sectors, primarily in North America. The data revealed 5,434 stolen credentials linked to 1,500 corporate email addresses, with 295 companies appearing in logs within the last 90 days.

ChatGPT dominated the dataset, accounting for 90% of all records across 358 companies, followed by developer-focused platforms like Hugging Face, Replit, and Zapier. Notably absent were Claude and Gemini, though researchers attributed this to ChatGPT’s first-mover advantage more employees use it on personal devices with work emails, making it a prime target. As adoption of other AI tools grows, so too will their exposure.

The risks of stolen AI logins extend beyond traditional credential theft. Unlike a single compromised password, an AI account serves as:

  • A searchable archive of sensitive corporate data (source code, contracts, unreleased plans).
  • An execution engine with automation capabilities (e.g., Zapier workflows).
  • A billable resource vulnerable to LLMjacking where attackers resell API keys or run fraudulent queries.
  • A live session that bypasses MFA via stolen cookies, persisting even after password resets.

Industries most affected include technology (40% of records), financial services, healthcare, and energy, with LLM exposure nearly universal in energy (93% of affected companies) and automation risks concentrated in healthcare and finance.

The report underscores that one unmanaged device with a saved AI login and a commodity infostealer is enough to compromise an enterprise. While controls like SSO with short-lived sessions, API key rotation, and session-token monitoring can mitigate risks, the challenge lies in shadow AI accounts credentials created outside IT oversight.

Anthropic’s response invalidating sessions, removing payment methods, and notifying affected users sets a precedent for how companies can react. The threat is not limited to any single AI platform but follows where employees use these tools, often outside corporate policies.

Source: https://www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/

OpenAI cybersecurity rating report: https://www.rankiteo.com/company/openai

Anthropic cybersecurity rating report: https://www.rankiteo.com/company/anthropic

"id": "OPEANT1790612921",
"linkid": "openai, anthropic",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of Claude AI assistant',
                        'industry': 'Technology',
                        'location': 'North America',
                        'name': 'Anthropic',
                        'size': 'Large',
                        'type': 'Company'},
                       {'customers_affected': 'Employees using AI services '
                                              'with corporate emails',
                        'industry': ['Technology (40%)',
                                     'Financial Services',
                                     'Healthcare',
                                     'Energy'],
                        'location': '36 countries (primarily North America)',
                        'size': '68% billion-dollar organizations',
                        'type': 'Companies'}],
 'attack_vector': 'Infostealer Malware',
 'customer_advisories': 'Anthropic notified affected users of forced sign-outs '
                        'and payment method wipes',
 'data_breach': {'data_exfiltration': 'Yes (via infostealer malware)',
                 'number_of_records_exposed': '5,434 stolen credentials (1,500 '
                                              'corporate email addresses)',
                 'personally_identifiable_information': 'Corporate email '
                                                        'addresses, '
                                                        'potentially other PII',
                 'sensitivity_of_data': 'High (corporate secrets, unreleased '
                                        'plans, PII)',
                 'type_of_data_compromised': ['AI service credentials',
                                              'Corporate data (source code, '
                                              'contracts)',
                                              'API keys',
                                              'Session tokens']},
 'date_detected': '2026-08',
 'description': 'In August 2026, Anthropic responded to a surge in '
                'infostealer-driven hijackings of its AI assistant, Claude, by '
                'forcibly signing out users, wiping saved payment methods, and '
                'refunding unauthorized charges. The incident highlighted a '
                'broader trend where cybercriminals increasingly target AI '
                'service credentials, with corporate employees as the primary '
                'victims. A SOCRadar AI Identity Exposure Report analyzed over '
                '1 million infostealer records tied to AI services across '
                '80,000+ corporate domains, revealing 5,434 stolen credentials '
                'linked to 1,500 corporate email addresses. The risks include '
                'sensitive corporate data exposure, automation misuse, '
                'LLMjacking, and live session persistence via stolen cookies.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'credential theft and data exposure',
            'data_compromised': ['Corporate data (source code, contracts, '
                                 'unreleased plans)',
                                 'API keys',
                                 'Session tokens'],
            'financial_loss': 'Unauthorized charges refunded by Anthropic',
            'identity_theft_risk': 'High (stolen corporate credentials)',
            'operational_impact': 'Forced user sign-outs, payment method '
                                  'wipes, and session invalidations',
            'payment_information_risk': 'High (saved payment methods wiped by '
                                        'Anthropic)',
            'systems_affected': ['AI assistant platforms (e.g., Claude, '
                                 'ChatGPT)',
                                 'Automation tools (e.g., Zapier)']},
 'initial_access_broker': {'entry_point': 'Unmanaged devices with saved AI '
                                          'logins',
                           'high_value_targets': 'Corporate employees using AI '
                                                 'services with work emails'},
 'investigation_status': 'Ongoing (as of report publication)',
 'lessons_learned': 'One unmanaged device with a saved AI login and '
                    'infostealer malware can compromise an enterprise. Shadow '
                    'AI accounts and lack of IT oversight exacerbate risks. '
                    'Controls like SSO, short-lived sessions, API key '
                    'rotation, and session-token monitoring are critical.',
 'motivation': ['Financial Gain', 'Data Exfiltration', 'LLMjacking'],
 'post_incident_analysis': {'corrective_actions': ['Session invalidation',
                                                   'Payment method wipes',
                                                   'Refunds for unauthorized '
                                                   'charges',
                                                   'User notifications'],
                            'root_causes': ['Infostealer malware on unmanaged '
                                            'devices',
                                            'Shadow AI accounts',
                                            'Lack of MFA enforcement',
                                            'Saved payment methods on AI '
                                            'platforms']},
 'recommendations': ['Enforce SSO with short-lived sessions for AI services',
                     'Rotate API keys frequently',
                     'Monitor session tokens for anomalies',
                     'Implement policies to manage shadow AI accounts',
                     'Educate employees on risks of saving AI logins on '
                     'personal devices'],
 'references': [{'source': 'SOCRadar AI Identity Exposure Report'}],
 'response': {'communication_strategy': 'Public disclosure via SOCRadar report '
                                        "and Anthropic's actions",
              'containment_measures': ['Forced user sign-outs',
                                       'Session invalidation',
                                       'Payment method wipes'],
              'incident_response_plan_activated': "Yes (Anthropic's forced "
                                                  'sign-outs, payment method '
                                                  'wipes, and refunds)',
              'remediation_measures': ['Refunding unauthorized charges',
                                       'Notifying affected users']},
 'title': 'Stolen AI Logins Expose Corporate Data in Growing Infostealer '
          'Threat',
 'type': 'Credential Theft',
 'vulnerability_exploited': 'Saved AI logins on unmanaged devices, lack of MFA '
                            'enforcement, shadow AI accounts'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.