Executive Summary
In August 2026, cybersecurity researchers analyzed a 7GB infostealer dump containing data from 5,871 infected machines across 162 countries, revealing thousands of unexpired authentication tokens for AI services including Google, OpenAI, Anthropic, and others. Information stealers like Lumma Stealer and Vidar harvested session tokens, API keys, and JSON Web Tokens (JWTs) that threat actors can replay to bypass credential-based authentication and multi-factor authentication, effectively gaining unauthorized access to premium AI services without traditional login processes. The stolen data included 555 AI-related JWTs and 2,937 encrypted tokens, with 17.7% containing plaintext personally identifiable information, enabling account takeovers, resource theft, and unauthorized AI service usage sold on underground markets.
This incident highlights the growing cybercriminal focus on AI credential theft as premium model access costs create strong financial incentives for stealing rather than purchasing legitimate access, while the proliferation of anti-detect browsers and session replay tools makes monetizing these stolen tokens increasingly accessible to threat actors.
Why This Matters Now
As AI adoption accelerates in enterprise environments, cybercriminals are increasingly targeting AI credentials and session tokens to bypass expensive premium model costs, creating a new attack vector that traditional MFA cannot prevent when session tokens are stolen and replayed.
Attack Path Analysis
Attackers deployed infostealers like Lumma Stealer and Vidar to harvest authentication tokens and API keys from victim systems. Stolen session tokens and JWT credentials were then replayed to bypass MFA and gain unauthorized access to AI services including OpenAI, Google, and Anthropic. Threat actors pivoted across multiple AI platforms using stolen credentials and anti-detect browsers to avoid security controls. Persistent C2 channels were established through compromised AI service accounts to maintain access. Attackers exfiltrated sensitive data including PII from JWT tokens and abused API keys for LLMjacking operations. The campaign resulted in unauthorized AI resource consumption, credential monetization on underground forums, and potential data exposure across 5,871 infected machines.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Infostealers like Lumma Stealer and Vidar infected 5,871 machines across 162 countries, harvesting credentials, session tokens, JWT/JWE tokens, and API keys for AI services
MITRE ATT&CK® Techniques
Credentials from Password Stores
Steal Web Session Cookie
Unsecured Credentials: Credentials In Files
Valid Accounts: Cloud Accounts
Phishing
Data from Cloud Storage Object
Exfiltration Over Web Service
Resource Hijacking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for All Users
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Strong Identity Authentication
Control ID: Identity Pillar 2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Infostealer malware targeting AI development platforms exposes authentication tokens, API keys enabling unauthorized access to premium AI services and compute resources.
Information Technology/IT
Session token theft bypasses MFA controls, compromising enterprise AI infrastructure and enabling resource hijacking through stolen authentication credentials and API keys.
Financial Services
AI token theft threatens financial modeling systems, exposing sensitive data through compromised authentication while enabling unauthorized access to premium computational resources.
Health Care / Life Sciences
Stolen AI authentication tokens compromise HIPAA compliance, exposing patient data through unauthorized AI service access and potential regulatory violations via token replay.
Sources
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFAhttps://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.htmlVerified
- Okta Threat Intelligence: Signing In Without Actually Signing Inhttps://www.okta.com/blog/threat-intelligence/signing_in_without_actually_signing_inVerified
- Google Chrome Rolls Out Device Bound Session Credentialshttps://thehackernews.com/2026/04/google-rolls-out-dbsc-in-chrome-146-to.htmlVerified
- Microsoft Exposes LLMjacking Attackshttps://thehackernews.com/2025/02/microsoft-exposes-llmjacking.htmlVerified
- TruffleHog Secret Scanning Toolhttps://github.com/trufflesecurity/trufflehogVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would be highly relevant to this AI service credential theft campaign as it could significantly reduce attacker lateral movement across cloud platforms and limit the blast radius of compromised AI service accounts through network segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility and monitoring capabilities would likely provide early detection of suspicious credential harvesting activities and abnormal authentication patterns across cloud-hosted AI services, potentially reducing the time attackers could operate undetected.
Control: Zero Trust Segmentation
Mitigation: Zero trust network segmentation would likely constrain the scope of access even with valid JWT tokens, limiting attackers to specific network segments and reducing their ability to access sensitive AI service resources across the entire cloud environment.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement between different AI service platforms and cloud environments, forcing attackers into more limited network paths and reducing their ability to pivot freely across multiple services.
Control: Multicloud Visibility & Control
Mitigation: Unified multicloud visibility would likely detect anomalous proxy-based connections and suspicious geographic access patterns across different AI platforms, potentially disrupting persistent command and control channel establishment through compromised accounts.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely limit unauthorized data extraction from AI service environments and constrain the volume of sensitive credential data that could be exfiltrated to external command and control infrastructure or underground marketplaces.
While some unauthorized AI resource consumption and credential sales could still occur, the overall financial impact and scope of LLMjacking operations would likely be significantly reduced due to constrained network access and limited lateral movement capabilities.
Impact at a Glance
Affected Business Functions
- AI/ML Development Operations
- API Service Management
- Customer Account Security
- Compute Resource Management
Estimated downtime: N/A
Estimated loss: N/A
Exposure of 44,791 JSON web tokens including 555 AI service authentication tokens, 2,937 encrypted JWE tokens, and 24 valid API keys for AI services. 17.7% of tokens contained plaintext PII including names, phone numbers, and email addresses affecting users across 162 countries from 5,871 infected machines.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security controls to detect and block unauthorized AI API communications and prevent token exfiltration to underground markets
- • Deploy zero trust segmentation with identity-based policies to limit lateral movement between compromised systems and AI service accounts
- • Enable multicloud visibility and anomaly detection to identify suspicious AI resource consumption patterns and LLMjacking activities
- • Enforce encrypted traffic controls and secure hybrid connectivity to protect authentication tokens in transit from infostealer harvesting
- • Establish threat detection capabilities to baseline normal AI usage patterns and alert on token replay attacks and anti-detect browser usage



