Okta’s threat intelligence team has published research showing that information-stealing malware is now routinely harvesting session tokens and API keys for AI services — and those stolen tokens can be replayed to bypass multi-factor authentication entirely.
The finding came from a 7 GB infostealer dump released on a Telegram channel in August. Among data from nearly 6,000 infected machines across 162 countries, Okta found thousands of unexpired authentication tokens for services including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Cursor, and others. On the day the dump was released, 1,843 tokens were still valid. An attacker with one of those tokens doesn’t need a password or an MFA code — they’re simply logged in.
This matters more than it would have a year ago. Australian businesses are rapidly connecting AI tools to company data — linking Claude to Microsoft 365, feeding client records into ChatGPT, running reports through Gemini. We’re seeing it across our client base. That changes what a stolen AI token is worth. It’s no longer just access to a chatbot. If the account is connected to your SharePoint, email, or Teams, a replayed token is a window into your business data that bypasses every access control you’ve set up.
Underground markets have already adapted. Okta flagged sellers on Telegram offering discounted access to Claude, ChatGPT, and Gemini accounts, complete with money-back guarantees and 24/7 support. Anti-detect browsers make replaying stolen sessions straightforward.
What to Do
Start with the basics: make sure AI tools are licensed through the business, not personal accounts. Use short-lived tokens where the platform supports them. Enforce endpoint protection on every machine that touches AI — infostealers like Lumma and Vidar are the entry point, and good endpoint detection catches them before tokens get harvested. And if you’ve connected an AI tool to company data, treat that AI account with the same seriousness as any other privileged access.
If you’re not sure what AI tools your staff are using or what they’re connected to, talk to us — that’s a question worth answering before an attacker answers it for you.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
