Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI User Accounts Targeted by Infostealer Logs

AI User Accounts Targeted by Infostealer Logs

Posted on September 9, 2026 By CWS

Cybercriminals are increasingly exploiting artificial intelligence (AI) user accounts by leveraging stolen information logs. These logs are used to create unauthorized access keys that bypass traditional security measures, including multi-factor authentication (MFA). This trend is particularly concerning for AI model providers such as Google and Anthropic.

Infostealers and Their Impact

Tools like Lumma Stealer and Vidar are designed to extract extensive data from compromised systems, including credentials, session tokens, and API keys. Once these sensitive data points are acquired, they are often sold in underground markets as ‘stealer logs’ for further exploitation by cybercriminals.

According to Jeremy Kirk, director of threat intelligence at Okta, session tokens and API keys are especially valuable to attackers. These elements can be replayed to bypass standard credential-based authentication, effectively granting unauthorized access to AI services without a legitimate login.

Analysis of Stolen Data

An analysis conducted by Okta on a 7 GB infostealer dump released on Telegram revealed data from 5,871 compromised devices across 162 countries. Among the stolen data were numerous unexpired authentication tokens related to major services like Google, Microsoft, and Amazon.

Out of 44,791 unique JSON web tokens (JWTs), 555 were connected to AI services. These tokens, along with JSON Web Encryption (JWE) structures, signify potential vulnerabilities, especially given that 17.7% contained plaintext personally identifiable information (PII).

Preventive Measures and Challenges

While IP allowlisting can mitigate session replay attacks, companies like Google are implementing Device Bound Session Credentials (DBSC) to restrict token usage to specific devices. Furthermore, tools like TruffleHog have exposed valid API keys for AI services, signifying ongoing risks.

This phenomenon, known as LLMjacking, involves attackers using stolen API keys to exploit large language models (LLMs) for espionage or resource theft. As AI adoption grows, so does the black market for stolen token bundles and anti-detect browsers.

Future Outlook and Recommendations

With the increasing expense of AI model access, the motivation for cybercriminals to steal credentials is intensifying. Google’s Mandiant team has observed increased targeting and exfiltration of AI accounts. The threat landscape demands enhanced security measures, including stronger authentication and the use of short-lived tokens.

To combat these threats, organizations must secure AI access, monitor for token misuse, and implement OAuth 2.0 flows. As cybercriminals continue to develop sophisticated methods, the importance of robust security protocols cannot be overstated.

The Hacker News Tags:AI security, API keys, API security, Cybersecurity, data breach, infostealer logs, LLMjacking, MFA bypass, session tokens, Threat Actors

Post navigation

Previous Post: Critical Patch for Windows Remote Desktop Flaw
Next Post: Fortinet Addresses Critical Security Flaws in Key Products

Related Posts

NadMesh Botnet Exploits AI Services for Cloud Credentials NadMesh Botnet Exploits AI Services for Cloud Credentials The Hacker News
Key Insights from Gartner’s Guardian Agents Guide Key Insights from Gartner’s Guardian Agents Guide The Hacker News
Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam The Hacker News
Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets The Hacker News
Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome The Hacker News
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattack Exploits PaperCut Vulnerabilities
  • Fortinet Addresses Critical Security Flaws in Key Products
  • AI User Accounts Targeted by Infostealer Logs
  • Critical Patch for Windows Remote Desktop Flaw
  • Meta Unveils AI Assistant Muse with Privacy Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattack Exploits PaperCut Vulnerabilities
  • Fortinet Addresses Critical Security Flaws in Key Products
  • AI User Accounts Targeted by Infostealer Logs
  • Critical Patch for Windows Remote Desktop Flaw
  • Meta Unveils AI Assistant Muse with Privacy Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark