AI
Published 2026-09-28
Verified 2026-09-29

SOCRadar AI Identity Exposure 2026: 80k+ domains in stealer logs; ChatGPT dominates 482-enterprise cut

SOCRadar Threat Research Unit AI Identity Exposure Report 2026 (amplified by BleepingComputer 28 Sep) analyses more than one million infostealer records tied to AI services across 80,000-plus corporate domains, then a verified cut of 482 established enterprises (68% billion-dollar; 36 countries; eight sectors). In that cut: 5,434 stealer-log records / 1,500 corporate emails; 295 of 482 seen in the last 90 days. ChatGPT/OpenAI sessions appear at 358 of 482 (~90% of records); Zapier, Notion, Hugging Face, Replit, Lovable, ElevenLabs trail; Claude/Gemini largely absent — framed as shadow-AI adoption skew, not vendor safety. Risks: conversation history as corporate memory; session cookies bypassing MFA; API-key LLMjacking; automation OAuth (e.g. Zapier) acting with employee authority. Distinct from desk okta-ai-token-infostealer-20260909 (token dump analysis) and anthropic-claude-infostealer-20260830 (Claude session drain); pairs with ACSC 28 Sep Protect AI services. Primary: SOCRadar report; wire: BleepingComputer 28 Sep.

Product
Enterprise AI accounts / sessions / API keys (ChatGPT, automation platforms, etc.)
Versions
n/a (research / exposure study; not a product CVE)
Exploited in Australia?
unknown
Patch to
SSO + short-lived sessions with refresh-token rotation for AI platforms; inventory shadow AI accounts on corporate domains; scope/cap/rotate API keys and alert on odd ASN/hours; session-reuse detection; treat stealer-log hits as endpoint incidents; revoke sessions and payment methods on compromise (Anthropic template).

Primary: SOCRadar — AI Identity Exposure Report 2026 · Vendor: SOCRadar Threat Research Unit · BleepingComputer — 80,000+ orgs AI logins stolen (28 Sep 2026)

ai identity australia