Stolen AI Logins Expose Data at 80,000 Organizations
A new report finds more than 80,000 organizations had employee logins for AI services stolen, with ChatGPT accounts most frequently compromised. Researchers identified 482 major enterprises, many billion-dollar firms, whose corporate credentials were sold in infostealer logs. Stolen AI accounts offer more than password access: attackers gain session history, execution rights, and sometimes billing capabilities, posing a greater threat to enterprise security.
- Over 80,000 organizations affected by AI account theft
- Researchers identified 482 major enterprises with compromised logins
- 68% of affected firms are billion-dollar organizations
- ChatGPT accounts made up 90% of breach records
- Stolen sessions bypass MFA and expose sensitive conversation history
Sources covering this
More in Cybersecurity
Dutch police arrest former hacker in ShinyHunters probe
Dutch police have arrested Pepijn van der Stap, a previously convicted hacker, in connection with an ongoing investigation into the…
Apple fixes CoreGraphics flaw after targeted attacks
Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly…
Critical zero-days in Citrix NetScaler exploited, patches released
Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited.
Security tool flags Kubernetes operator privilege risks
Palo Alto Networks' Unit 42 released OperTraitor, an open-source tool that uses a language model to analyze Kubernetes operator…