Criminals Can Open AI Accounts Without a Password. MFA Doesn't See It Happen.


Yesterday we wrote about phishing kits that steal Microsoft 365 sessions after MFA. Today, the same outcome by a different route, aimed at a newer target: the AI accounts your team uses every day. New research from Okta looked inside a leaked trove of data stolen from infected computers and found live session tokens and API keys for AI services, ready to be replayed. An attacker who replays one opens the account without a password and without triggering MFA, and can read what your team has pasted inside.
What the researchers found
In early August, a 7 GB bundle of data stolen by infostealer malware was released on Telegram, covering 5,871 infected machines across 162 countries. Okta's threat intelligence team dug through it and pulled out 44,791 unique authentication tokens, the digital passes that keep you signed in to a website so you do not retype your password every visit. Of those, 555 were likely tied to AI services, and the trove also held 2,937 encrypted tokens plus 24 still-valid API keys across four services. On the day the dump was released, 1,843 of the tokens and encrypted tokens combined had not yet expired, still inside their validity window and potentially replayable.
The services involved read like your team's browser tabs: the tokens pointed to Google, Microsoft, Anthropic, Amazon, Notion, Cursor, and a string of smaller AI tools, and the still-valid API keys belonged to services including Google Gemini, OpenAI, Groq, and OpenRouter. Across the full set of 44,791 tokens, 17.7 percent, about one in six, also carried personal information in plain text: names, emails, and phone numbers, bundled free with the theft.
Why MFA stays silent
The malware behind this, families with names like Lumma Stealer and Vidar, does not guess passwords. It infects a computer, often arriving through a phishing email, a malicious ad, or a poisoned download (the reporting does not say how these particular machines were infected), and copies what the browser has already stored: saved passwords, cookies, and the session tokens that prove to a website that you already logged in.
Replaying a stolen session token skips the entire login ceremony. There is no password prompt, so a strong password does not matter. There is no MFA prompt, so the authenticator app stays silent. As Okta's Jeremy Kirk puts it, a successful replay means a threat actor is "effectively logged in to an LLM service without actually logging in." There is often nothing visible to the account owner, and Okta notes this kind of abuse is harder, though not impossible, to detect.
If that sounds familiar, it is the same reason adversary-in-the-middle phishing works after MFA: modern account theft increasingly skips credentials and steals the signed-in state itself.
Why this lands on a 10-to-500 person business
Ask what is actually inside a work AI account, because that is what the token unlocks. Months of chat history. The contract a manager pasted in for a summary. The client list someone asked to have cleaned up. The financials pasted in for a chart, the source code pasted in for a debug. An attacker reading chat history does not need to hack your file server; your team already curated the highlights into one place.
API keys are their own problem: a stolen key lets an attacker run their own workloads on your billing, and the meter runs until someone notices the invoice.
And here is the multiplier for smaller businesses. Verizon's 2026 data breach report found that 67 percent of users are using non-corporate accounts on their corporate devices to access AI services. A personal ChatGPT account with two years of work pasted into it is invisible to the business: nobody can reset its sessions, nobody is watching its sign-ins, and almost nobody is positioned to find out when it is breached. IBM's 2026 breach study, meanwhile, found 68 percent of breached organizations had no AI governance policy in place. The accounts are full of company data, and in most businesses, nobody owns the problem.
What actually helps
The researchers' own recommendations center on making stolen tokens worthless: phishing-resistant sign-in such as passkeys, short-lived tokens that expire quickly, and watching for token reuse. For a small and medium business, that translates into four practical moves. Turn on passkeys where your AI and cloud services support them. Use the "sign out of all devices" option in a service's security settings after anything suspicious, because for most major services that revokes the sessions a stealer may have copied, though some tokens stay valid until they expire, which is exactly why the researchers push short-lived tokens. Treat API keys like cash: scope them narrowly, rotate them on a schedule, and delete the ones nobody remembers creating. And know which AI accounts exist in your business at all, because you cannot reset a session on an account you do not know about. If your team needs a starting point for that last one, we wrote a five-step AI governance framework for exactly this.
Where we fit
This is one of the few threats that crosses everything we do, so here is the honest map. The infostealer has to land on a machine first: our Managed Endpoint Protection (powered by SentinelOne) watches behavior on the machines themselves, which is where stealers do their work. The most common way it arrives is a link or attachment: our Managed Email Security inspects both behind Microsoft's own filtering, as a second and different layer. The accounts it targets are the AI tools your team already uses, sanctioned or not: our Managed AI Security starts with discovery, building the inventory of AI in use from what we actually find, so the invisible personal-account problem stops being invisible. And when exposed credentials from your domain surface in the places stolen data gets traded, our dark web monitoring add-on alerts us so those accounts can be locked down.
No single one of those layers ends this threat, and we will not pretend otherwise. The point of the stack is that a stealer has to get past the email layer, then the endpoint layer, then still find accounts nobody inventoried, and even then, monitoring watches for your domain's exposed credentials. Behind all of it, a named engineer watches the dashboards and acts on what they flag.
The question worth asking this week
Not "do we use AI," because your team already does. Ask this instead: if a criminal opened one of your team's AI accounts today and read the chat history, what would they be holding, and would anyone ever know it happened?
We work with small and medium businesses nationwide from our home base in McLean, Virginia. If you are in Washington DC, Northern Virginia, Maryland, or anywhere in the country and that question has no comfortable answer, book a free 15-minute call. We will show you what an AI account discovery looks like for a business your size, and what an exposure check for a domain like yours looks like.
Comments