1,000,000+
infostealer records tied to AI services
All of that is the supply side of a market. SOCRadar’s AI Identity Exposure Report 2026 is a look at the demand side — the enterprises whose employees are the credentials being sold.
The security industry spent the summer of 2026 learning a phrase it will not forget: the stolen AI login. In late August, Anthropic signed users out of Claude, wiped saved payment methods and refunded fraudulent charges after infostealer malware began hijacking Claude sessions to drain paid usage — a move users first surfaced on Reddit when their limits “refilled and then drained” while they slept. Days later, Okta researchers pulled a 7 GB stealer dump off Telegram and found thousands of replayable tokens inside, including two dozen still-valid API keys for major AI providers. Google’s threat group, meanwhile, published a tracker describing adversaries moving “from prompting to autonomy.”
1,000,000+
infostealer records tied to AI services
All of that is the supply side of a market. SOCRadar’s AI Identity Exposure Report 2026 is a look at the demand side — the enterprises whose employees are the credentials being sold.
80,000+
unique corporate domains
Drawing on a collection of more than one million infostealer records tied to AI services across 80,000-plus unique corporate domains.
482
established enterprises
The research narrows to a verified cross-section of 482 established enterprises to answer a blunt question: when an AI login lands in a stealer log, whose is it, and what does the buyer inherit?
68%
of the major 482 are billion-dollar organisations
The answer is uncomfortable. They span technology, industrials, financial services, healthcare, energy and retail, sit in 36 countries — predominantly North America — and include dozens of Forbes-ranked corporations.
295
of the 482 companies surfaced in stealer logs within the last 90 days
Between them they account for 5,434 stealer-log records tied to 1,500 distinct corporate email addresses, and the exposure is fresh.
Break the dataset down by platform and one name swallows the chart. A captured ChatGPT or OpenAI session shows up for 358 of the 482 companies — and those companies carry roughly 90% of all the records in the study. Everything else — Zapier, Notion, Hugging Face, Replit, Lovable, ElevenLabs — trails far behind.
That skew is a story in itself — and the more interesting part of it is who is missing. There is no Claude in the top ranks. No Gemini.
“We read the near-total dominance of ChatGPT as a shadow-AI signal, not a verdict on any vendor’s security. ChatGPT’s first-mover advantage means it likely has an order of magnitude more corporate users — many of them signing up with a work email on a personal device, outside any policy. That is exactly the population infostealers scrape. Claude and Gemini barely appear because far fewer employees have quietly created accounts on them yet — not because those credentials are safer to steal. As enterprise adoption of other assistants catches up, we expect this chart to even out.”
For a research team, that absence is the finding, not a gap.
It is a timely caveat. Anthropic’s own late-August incident showed Claude sessions are targeted the moment they exist in enough volume; the platform simply has a smaller corporate footprint to harvest today. The lesson for a CISO is not “pick a safer assistant.” It is that the exposure follows the users, and the users are everywhere your policy isn’t.
A traditional credential unlocks one app. An AI account is four things at once — a searchable archive, an execution engine, a billable resource and an identity — and the stolen session hands over all of them without a password prompt.
Employees paste source code, customer records, contracts and unreleased plans into prompts. AI is no longer only a tool; it becomes a point of corporate memory. An attacker who replays the session inherits that archive before touching a single internal system.
A stolen cookie is a live session. As Okta’s Jeremy Kirk put it, “session tokens and API keys are sought specifically by threat actors because it is often possible to replay those secrets and bypass credential-based authentication.” Rotating the password alone leaves the intruder signed in.
Keys copied into a notes app or a workspace settings page get lifted with everything else, then billed to the victim or resold. Underground vendors sell discounted access to Claude, Gemini and Cursor accounts and money-back guarantees.
Automation platforms hold standing OAuth grants into CRM, email and storage. A stolen Zapier session lets an attacker build a workflow that exfiltrates data on a schedule, from a vendor’s trusted IP space.
The same week SOCRadar compiled this data, Anthropic, Google and Microsoft each published research showing threat actors using AI to research and exploit vulnerabilities — the capability everyone is watching after the arrival of Mythos-class models. Just as important, and less discussed: adversaries now use AI to harvest, validate and organise credentials at scale. Google’s GTIG documented a single agentic campaign that stood up a credential-harvesting pipeline across thousands of services in under six hours, with a C2 dashboard tracking 23,800+ stolen secrets. The stealer logs in this report are the raw material that feeds exactly that machine.
The affected companies are not a niche. Technology and internet-services firms are the single largest group at 144 companies and 40% of all records which hold the data of many downstream clients. But industrials, financial services, retail, healthcare and energy all appear in force.
Break the same sectors down by what kind of AI is exposed and the risk profile shifts. LLM-platform (ChatGPT) exposure is near-universal everywhere — highest in energy at 93% of affected companies. But agent and automation exposure, the category that carries an employee’s authority into other systems, concentrates in the sectors that can least afford it: healthcare, financial services and technology.
0%
Highest in energy, at 93% of affected companies.
Concentrates in the sectors that can least afford it:
All of this lands in the middle of a very loud argument. On September 12, Anthropic CEO Dario Amodei published an essay calling for the industry to slow the pace of AI development, warning that rogue agent swarms could cause enormous damage within a year; Sam Altman and Elon Musk broadly agreed. That debate is about frontier capability. This report is about plumbing — and the plumbing is leaking now, with tools that have existed for years.
You do not need an autonomous swarm to lose your corporate memory.
You need one employee, one unmanaged laptop, one saved ChatGPT password and one commodity infostealer that has been on sale in Telegram channels since 2022.
The frontier-risk conversation and the credential-hygiene conversation are not competitors; the second is the one a CISO can act on this quarter.
The controls are not exotic. What is new is that AI platforms now belong in the same tier as your identity provider and your code repositories.
Use OAuth 2.0 / OIDC and refresh-token rotation so a stolen cookie expires before it can be sold. Note SSO’s limit: it removes the saved password, not the live session cookie, and it does nothing for accounts staff opened with a work email before the policy existed.
A session that changes country or device fingerprint mid-life is a replayed session. Treat any employee appearing in a stealer log as an endpoint incident, not a password reset.
You cannot rotate what you don’t know exists. Start by finding which of your domains already appear in stealer logs.
See if your organisation appears in the AI stealer logs behind this report — platforms, record counts, recency. No signup.
Run AI Identity Exposure CheckAnthropic’s response to its own incident is the template worth copying: it did not stop at advising a password change, it invalidated sessions, stripped the payment methods attackers were abusing, and proactively notified the people whose machines were infected. That last step — telling an affected user their machine is compromised before the next session is stolen — is the difference between an intelligence feed and a fire alarm.
For most of the 482, that call will have to come from inside.