AI accounts have become another target for infostealer malware. According to a SOCRadar report, researchers found more than one million records involving AI services and over 80,000 corporate domains. That does not mean every organization was breached. It means credentials or sessions associated with those domains appeared in the data researchers examined.
SOCRadar took a closer look at 482 large companies. Within that group, researchers identified 5,434 infostealer records connected to 1,500 unique work email addresses. Records associated with 295 of the companies had appeared within the previous 90 days.
ChatGPT Accounts Appear Most Often
ChatGPT or OpenAI credentials and sessions appeared in records associated with 358 of the 482 companies. Researchers also found exposure involving Hugging Face, Replit, Notion, and Zapier. ChatGPT’s larger share may reflect how widely employees use it, including through accounts their employers do not manage. The figures do not show that one platform is less secure than another.
Stolen Sessions Can Put Account Data at Risk
Infostealer malware can capture an active browser session along with saved passwords. An attacker who reuses that session may be able to access an account without completing a new login. Work conversations, uploaded files, API keys, and connected business tools could then be at risk.
In August 2026, Anthropic warned that malware had stolen some users’ Claude sessions. The company signed affected users out, removed saved payment methods, and refunded charges it identified as unauthorized.
What Security Teams Should Check
Organizations should identify AI accounts registered with company email addresses and investigate any that appear in infostealer records. If an account is exposed, security teams should revoke active sessions, rotate affected credentials and API keys, review recent activity, and check connected applications. They should also inspect and clean the employee’s device so malware cannot capture the next session.

