elevated Llmjacking · AI Security

Stolen ChatGPT Logins Turned Up at 358 of 482 Big Companies

Data graphic: 358 of 482 big firms had a stolen ChatGPT or OpenAI login or session in infostealer logs; 80,000+ corporate domains, 295 firms seen in the last 90 days, 1,500 corporate emails exposed.
AK

Threat intelligence editor · Updated Oct 2, 2026, 8:05 AM EDT

SOCRadar tied over a million infostealer records to AI services. In 358 of 482 large enterprises it studied, a ChatGPT or OpenAI login had been stolen.

Infostealer logs are full of AI logins, and most of them are ChatGPT. SOCRadar's AI Identity Exposure Report, published on 28 September 2026, says the threat-intelligence firm found more than one million infostealer records tied to AI services across more than 80,000 corporate domains. It then studied 482 large enterprises closely. At 358 of them, at least one employee's ChatGPT or OpenAI credential or session had been captured.

The figures come from SOCRadar's own dataset, and SOCRadar sells the monitoring that finds them. ThreatFrontier read them in a sponsored post on BleepingComputer that SOCRadar wrote. We could not open the full report on SOCRadar's site, which sits behind a bot check, so every number below is as SOCRadar published it in that post and in its report summary.

What the report counted

SOCRadar started from more than a million stealer-log records that hold a login, cookie or key for an AI service. It mapped them against corporate email domains and got more than 80,000 domains. From those it picked 482 "major established enterprises" for a closer look:

  • 68% of the 482 are billion-dollar organisations. They are spread across 36 countries and eight sectors, mostly in North America.
  • Together they account for 5,434 stealer-log records tied to 1,500 distinct corporate email addresses.
  • 295 of the 482 turned up in logs from the last 90 days. For them the exposure is recent, not historical.

ChatGPT dominates

Split the 482 by platform and one name stands out. A captured ChatGPT or OpenAI login or session appears at 358 companies, about three in four. Those companies hold roughly 90% of all records in the study. Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs come next, far behind. Claude and Gemini are not near the top.

SOCRadar reads that as a sign of shadow AI, not as a verdict on OpenAI's security. ChatGPT got there first, so far more employees signed up with a work email on a personal device, and that is the population infostealers scrape. The firm expects the other assistants to catch up as their adoption grows.

Data graphic: lollipop chart of companies out of 482 studied: all 482, 358 with a stolen ChatGPT or OpenAI login, 295 seen in the last 90 days, 144 tech and internet firms; those 358 hold about 90% of all records.

Of 482 large enterprises SOCRadar studied, 358 had a stolen ChatGPT or OpenAI login or session. Source: SOCRadar AI Identity Exposure Report 2026.

Why a stolen AI session is worse than a password

A stolen password usually unlocks one app. A logged-in AI account holds four things at once:

  1. An archive. Employees paste source code, customer records, contracts and unreleased plans into prompts. Whoever replays the session can read that history without touching an internal system.
  2. A live session. Infostealers take the browser's session cookie along with the saved password. A replayed cookie is already past MFA, and changing the password does not sign the intruder out.
  3. Delegated authority. Automation platforms such as Zapier hold standing OAuth grants into CRM, mail and storage. With a stolen session an attacker can build a workflow that exports data on a schedule from the vendor's own IP space.
  4. A bill. API keys saved in a notes app or a workspace settings page are taken along with everything else. They are then billed to the victim or resold. This is LLMjacking, the same abuse ThreatFrontier covered on the server side with TensorFold's unauthenticated API.

Where the exposure sits

Technology and internet-services firms are the largest group: 144 companies and 40% of all records. Many of them hold data for their own customers downstream. Industrials, financial services, retail, healthcare and energy also appear in large numbers. Exposure of LLM chat platforms is close to universal across sectors. It is highest in energy, where 93% of the affected companies had one. Exposure of agent and automation platforms, the kind that carries an employee's authority into other systems, clusters in healthcare, financial services and technology.

None of this needs an advanced attacker. One employee, one unmanaged laptop, one ChatGPT password saved in the browser and an infostealer bought from a Telegram channel are enough.

What defenders should do

  • Count AI accounts as identities. Put ChatGPT, Claude, Gemini, Zapier, Notion and the rest in the same tier as your identity provider and code repositories, and keep an inventory of who has an account.
  • Find the shadow accounts first. You cannot rotate what you do not know about. Check whether your domains appear in stealer logs, through your threat-intelligence provider or SOCRadar's free domain checker.
  • Use SSO with short sessions. Use OAuth 2.0 or OIDC with refresh-token rotation, so a stolen cookie expires before it can be sold. SSO removes the saved password, but not a live cookie, and it does nothing for accounts opened before the policy existed.
  • Scope, cap and rotate API keys. Alert on use from unfamiliar networks (ASNs) or at odd hours, which is the usual sign of LLMjacking.
  • Watch for session replay. A session that changes country or device fingerprint partway through has been replayed. Treat an employee who appears in a stealer log as an infected endpoint: reimage the machine and revoke every session, not just the password.

Sources

Keep reading

All latest →
  1. elevatedAI SecurityOpenAI Says Moonshot-Linked Accounts Replayed Encrypted Reasoning to Distill Its Models5 min
  2. highAI SecurityCARBONATO Botnet Turns Exposed Docker Hosts Into Hermes Agent Bots That Hunt AI Keys6 min
  3. elevatedAI SecurityPixelLeak: AI Coding Agents Pushed 13,000 Internal Screenshots to Public GitHub Repos7 min
  4. highAI SecurityOpenAI Pauses Tool Use on Its Most Capable Models After a Training Agent Escaped Through DNS8 min
  5. highAI SecurityPlugin4Shell: A Pinned Commit SHA Didn't Stop Repo Owners Swapping Plugin Code in Claude Code, Codex, Copilot and Gemini CLI6 min
  6. highAI SecurityOfficial MCP Python SDK Let Malicious Servers Steal OAuth Secrets, and Upgrading Isn't Enough7 min