Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Stolen AI Session Tokens Can Bypass Passwords and MFA, Research Warns

Stolen AI Session Tokens Can Bypass Passwords and MFA, Research Warns

By: Morgan Cipher — Senior Privacy Journalist

Last updated: September 10, 2026

Human Written
Stolen AI Session Tokens Can Bypass Passwords and MFA, Research Warns
  • Hackers found a way to break into AI accounts without ever typing a password.

  • Security firm Okta found 555 stolen login codes tied to tools like Google, Anthropic, and more.

  • A new black market now sells access to Claude, ChatGPT, and Gemini accounts at cheap prices.

Criminals no longer need your password to get into your AI account. They only need a stolen digital key. Researchers found thousands of these keys inside a leaked data file.

Someone posted the file on the messaging app Telegram. It held private data stolen from thousands of infected computers.

Inside the Leaked Data File

Identity security firm Okta studied a leaked file shared on August 2, 2026. The file measured about 7 gigabytes in size. Tools known as infostealers, such as Lumma Stealer and Vidar, built the file. These programs quietly pull passwords, login codes, and private data from infected machines.

Okta traced the data back to 5,871 infected computers. Those machines sat in 162 different countries. Many belonged to people who use AI tools every day.

The leak held 44,791 login codes called JSON Web Tokens, or JWTs. Researchers linked 555 of them to AI platforms. Affected services included Google, Microsoft, Anthropic, Amazon, Notion, Character.ai, Cursor, Poe.com, and Pika AI.

Okta also spotted 2,937 encrypted login codes, known as JWEs. Most came from OpenAI’s sign-in system. These codes stay locked and hard to read. Still, a hacker can reuse an encrypted code and get in, as long as it has not expired.

By the day the file leaked, 1,843 of the stolen codes still worked. That number worried researchers. Worse, 17.7 percent of every JWT carried plain personal details. This included names, phone numbers, and email addresses linked to real people.

Okta’s threat intelligence director, Jeremy Kirk, explained that criminals chase these codes on purpose. Reusing a stolen code can log a hacker in without touching a password screen. According to Kirk, this trick makes break-ins far harder for security teams to catch.

A global breach exposed 149 million passwords along with usernames, email addresses, and other login data. Compiled from infostealer campaigns, the dataset has fueled identity theft and credential-stuffing attacks, highlighting the value of stolen credentials on the dark web.

Beyond login codes, researchers also ran a scanning tool called TruffleHog on the same file. They found 24 working access keys for AI services. Those included Google Gemini, OpenAI, Groq, and OpenRouter. A hacker holding one of these keys can spy on private data, demand money, or simply run up someone else’s bill.

A Growing Black Market for AI Accounts

Security researchers gave this kind of theft a name: LLMjacking. It works much like old cryptocurrency mining scams. A criminal quietly uses someone else’s account and leaves the real owner to pay the bill. Premium AI tools cost real money to run. That price tag pushes some criminals toward theft instead of payment. A stolen key hands them free access to powerful software.

Special tools help criminals do this smoothly. So-called anti-detect browsers hide the signs of a stolen login. Programs like Camoufox and SeleniumBase can pull stolen browser data straight from a saved file. These tools also route traffic through proxies. That trick helps hackers dodge alerts tied to logins from unusual places.

Some defenses still work against this attack. Companies that use IP allowlisting only accept logins from approved networks. Google also built a Chrome feature called Device Bound Session Credentials. This feature locks a login code to one single device, so a stolen copy becomes useless elsewhere.

A shadow market has grown around this trend too. One seller advertised cut-price access to Claude, Cursor, ChatGPT, and Gemini. That seller even promised round-the-clock support and money-back guarantees. Another service, calling itself Poison Claude, claimed to sell entries into several Anthropic models.

Google’s own threat team backs up these findings. The company reported seeing more buyers and sellers trading AI account access across hacker forums. Coding tools such as Cursor Pro and Devin showed up in demand too.

Google’s Mandiant response team already handled a real case tied to this trend. A hacker broke into a company’s cloud system using a leaked GitHub access token. The hacker then set up unapproved AI tools and used the company’s own computing power for free, referencing this cost problem in a related report on hidden AI expenses.

Steps Companies can Take Now

Businesses that rely on AI tools need stronger habits around login safety. Security teams should watch closely for reused login codes across their systems. They should also limit what each access key is allowed to do.

Short-lived login systems help a great deal here. The OAuth 2.0 standard offers codes that expire on their own within minutes. A stolen code becomes worthless the moment its short timer runs out.

Passwordless login methods, known as passkeys, also raise the bar for attackers. They stop plain password theft in its tracks. Even so, Kirk noted that passkeys alone cannot stop a stolen session token or a leaked access key. As frontier AI models grow pricier, he added, the reward for stealing access grows right alongside them.

The pattern here stays simple. As AI tools become more valuable, criminals will keep hunting for shortcuts around them. Companies that track their login codes closely and retire old keys fast stand the best chance of staying safe from this new wave of AI account theft.

Share this article

You might also like

Nearly 40,000 Twitch Streamers Targeted in Alleged Data Scrape

Nearly 40,000 Twitch Streamers Targeted in Alleged Data Scrape

A seller claims to have personal data on almost 40,000 Twitch streamers, including emails, legal names, and follower counts. Twitch…

September 10, 2026
Linux Rootkit Hides PHP Web Shell in F5 BIG-IP APM Memory

PoisonedRefresh Linux Rootkit Hides Fileless PHP Web Shell in F5 BIG-IP APM Memory

Researchers have found a Linux rootkit that hides a PHP web shell in Apache’s memory on F5 BIG-IP APM devices.…

September 10, 2026
Hacker Claims Live Access to Transfast Portal with 11 8 Million SMS Records

Hacker Claims Live Access to Transfast-Linked Portal With 11.8 Million SMS Records

A forum actor claims to have live access to a Transfast messaging portal with more than 11.8 million SMS records.…

September 10, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.