80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer malware has captured AI platform credentials and active sessions linked to more than 80,000 corporate domains, exposing companies to risks that include leaked conversation histories and attackers using stolen access to run AI workloads at the victim's expense, a practice known as LLMjacking.
Why this matters: Most companies do not know their employees are logging into AI tools with corporate accounts until those credentials show up for sale. When they do, the damage is not just a billing problem. Stolen AI sessions can expose internal conversations, business strategies, and whatever sensitive material employees fed into the tool. LLMjacking adds a financial hit on top of that. The core issue is that shadow AI use gives security teams no visibility and no way to respond. You cannot protect access you did not know existed.
Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.