Ethical Hacking News
Infostealers are targeting AI accounts, exposing corporate secrets and sensitive data. A recent report by SOCRadar reveals that nearly 400 companies have exposed their AI accounts and credentials, resulting in 482 companies being affected. The report highlights the growing threat of infostealers targeting AI accounts, which are becoming increasingly valuable to hackers. Companies must take proactive measures to protect their AI accounts and prevent the theft of sensitive data and connected systems.
Nearly 400 companies have exposed their AI accounts and credentials, with 482 companies affected by AI account exposure. 295 companies had active AI account exposure during the last 90 days, with 5,434 stealer log records linked to 1,500 distinct corporate email addresses. Chatbots are particularly vulnerable to infostealers, with a captured chatbot session appearing at 358 of the 482 companies. Automated platforms make AI account exposure worse, allowing attackers to exfiltrate data on a schedule without further credential theft. Technology firms are the largest group affected by AI account exposure, with 144 companies and 40% of all records. The exposure of AI accounts requires immediate attention, and companies should implement robust security measures to protect their accounts. Recommended controls include putting AI platforms behind single sign-on, limiting API keys, and flagging unusual activity.
Artificial intelligence (AI) accounts have become the new target for infostealers, exposing corporate secrets, sensitive data, and connected systems. According to a recent report by SOCRadar, nearly 400 companies have exposed their AI accounts and credentials, resulting in 482 companies being affected by AI account exposure. The report highlights the growing threat of infostealers targeting AI accounts, which are becoming increasingly valuable to hackers.
The study, which analyzed stealer log data from the last 90 days, found that 295 companies had active AI account exposure during the period, suggesting that the exposure is recent rather than the result of historical cleanup. The affected companies account for 5,434 stealer log records linked to 1,500 distinct corporate email addresses.
The report reveals that chatbots, such as ChatGPT and OpenAI, are particularly vulnerable to infostealers. A captured chatbot session appeared at 358 of the 482 companies, accounting for roughly 90% of all records in the study. This highlights the need for companies to implement robust security measures to protect their AI accounts.
The study also notes that automation platforms make the exposure worse. A stolen Zapier session carries standing authorization into CRM systems, email, and file storage. An attacker with access can build a workflow that exfiltrates data on a schedule, from a trusted vendor IP address, without any further credential theft required.
The sector breakdown reveals that technology firms are the largest group at 144 companies and 40% of all records, which matters because those companies hold downstream client data too. However, industrials, financial services, healthcare, retail, and energy all appear in force.
The report emphasizes that the exposure of AI accounts is a serious issue that requires immediate attention. The industry needs to treat the exposure of AI accounts as a separate and distinct issue from password breaches. A stolen AI login is categorically different from a stolen password, and the report highlights the risks associated with AI account exposure.
The recommended controls are straightforward. Companies should put AI platforms behind single sign-on, use short-lived sessions and rotate refresh tokens so stolen cookies expire quickly. They should limit and regularly rotate API keys, and flag activity from unusual locations or outside normal working hours. If an employee shows up in a stealer log, it should be treated as an endpoint security incident, not simply a password reset.
The report concludes that the exposure of AI accounts is a real and immediate concern that requires action. Companies must take proactive measures to protect their AI accounts and prevent the theft of sensitive data and connected systems.
Related Information:
https://www.ethicalhackingnews.com/articles/Ai-Accounts-Are-Becoming-the-New-Target-for-Infostealers-Exposing-Corporate-Secrets-ehn.shtml
https://securityaffairs.com/199933/ai/ai-accounts-are-becoming-the-new-target-for-infostealers.html
Published: Mon Sep 28 16:12:20 2026 by llama3.2 3B Q4_K_M