Security1 publisher2 min readPublished
Stolen ChatGPT sessions turn up at 358 of 482 companies in SOCRadar's stealer-log study
SOCRadar found captured ChatGPT sessions at 358 of the 482 companies whose AI accounts turned up in 90 days of infostealer logs. The firm ties the spread to shadow AI, with employees opening work-email accounts that IT never sees.
The Watch · Security desk

What happened
- Of the 482 companies, 295 appeared in logs that were still active during the 90-day window, a sign the infections are recent.
- The data set holds 5,434 stealer-log records tied to 1,500 distinct corporate email addresses.
- Okta researchers pulled a 7 GB stealer dump off Telegram and found thousands of still-replayable tokens, including two dozen valid API keys for major AI providers.
- In late August, infostealers hijacked Claude sessions to drain paid usage, and Anthropic responded with a company-wide sign-out, payment method removals and fraud refunds.
- Between July and September 2026, underground forums openly offered Claude API keys, paid and Pro ChatGPT cookies and Cursor sessions, some with money-back guarantees.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Incident response that stops at a password reset leaves the intruder signed in to the AI account, so the live session has to be revoked as well.
- exposure Anyone replaying a ChatGPT session can read the prompt history, including pasted source code, customer data and contracts, without breaking into internal systems.
- cost Stolen API keys run AI workloads on the victim's bill or get resold at a discount, so the company pays for the attacker's compute.
- decision Security teams can only revoke sessions on accounts they know exist, so the work starts with finding AI accounts opened on corporate email outside IT's view.
Anyone holding these logs has the browser session itself. "A stolen cookie is a live session," SOCRadar wrote in the report [10]. Okta researcher Jeremy Kirk, cited in the report, said "session tokens and API keys are sought specifically by threat actors because it is often possible to replay those secrets and bypass credential-based authentication." [11]
ChatGPT dominates the set. Its 358 companies are 74% of the 482 [4][1]. ChatGPT sessions also make up roughly 90% of all records, with Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs far behind [5]. The records average about 3.6 per exposed corporate address [2]. Technology firms are the largest group at 144 companies, about 30% of the set, yet they account for 40% of records [17][3]. Security Affairs notes those firms also hold downstream client data [17]. Industrials, financial services, healthcare, retail and energy companies appear in large numbers too [18].
Security Affairs, summarizing the report, says the ChatGPT figure does not necessarily point to a security problem at OpenAI. It attributes the figure to employees using work-email accounts on personal devices outside company policy [6]. The published account does not break out how many infected machines were personal and how many were managed. SOCRadar makes the same argument about Claude and Gemini, which barely appear. It reads their absence as a shadow-AI signal, not as evidence those platforms are safer to steal from [7]. According to Security Affairs, attackers go after Claude sessions as soon as there are enough of them, and corporate environments hold fewer of them today [20]. When stealers hit Claude accounts in late August, Reddit users saw usage limits that "refilled and then drained" overnight [9].
Automation accounts reach further than chat. A stolen Zapier session carries standing authorization into CRM, email and file storage [16]. With it, an attacker can build a workflow that pulls data out on a schedule, from a trusted vendor IP address, with no further credential theft [16].
The keys and cookies come off infected machines. They "get lifted with everything else," the report says [15]. Taken together, the Okta dump, Anthropic's forced sign-out and three months of forum listings with money-back guarantees show an ongoing trade in access to several AI providers [12][8][14].
What to watch
- A SOCRadar breakdown of how many infected machines were personal versus managed would test the shadow-AI explanation directly.
- Whether OpenAI or other providers follow Anthropic's August response with forced sign-outs for sessions found in stealer logs.
- Whether Claude and Gemini sessions rise in stealer logs as corporate use grows, as SOCRadar's volume reading predicts.