Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Dark navy graphic with headline Your AI Account Is Now a Target — infostealers harvesting AI session tokens

Okta’s threat intelligence team has published research showing that information-stealing malware is now routinely harvesting session tokens and API keys for AI services — and those stolen tokens can be replayed to bypass multi-factor authentication entirely.

The finding came from a 7 GB infostealer dump released on a Telegram channel in August. Among data from nearly 6,000 infected machines across 162 countries, Okta found thousands of unexpired authentication tokens for services including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Cursor, and others. On the day the dump was released, 1,843 tokens were still valid. An attacker with one of those tokens doesn’t need a password or an MFA code — they’re simply logged in.

This matters more than it would have a year ago. Australian businesses are rapidly connecting AI tools to company data — linking Claude to Microsoft 365, feeding client records into ChatGPT, running reports through Gemini. We’re seeing it across our client base. That changes what a stolen AI token is worth. It’s no longer just access to a chatbot. If the account is connected to your SharePoint, email, or Teams, a replayed token is a window into your business data that bypasses every access control you’ve set up.

Underground markets have already adapted. Okta flagged sellers on Telegram offering discounted access to Claude, ChatGPT, and Gemini accounts, complete with money-back guarantees and 24/7 support. Anti-detect browsers make replaying stolen sessions straightforward.

What to Do

Start with the basics: make sure AI tools are licensed through the business, not personal accounts. Use short-lived tokens where the platform supports them. Enforce endpoint protection on every machine that touches AI — infostealers like Lumma and Vidar are the entry point, and good endpoint detection catches them before tokens get harvested. And if you’ve connected an AI tool to company data, treat that AI account with the same seriousness as any other privileged access.

If you’re not sure what AI tools your staff are using or what they’re connected to, talk to us — that’s a question worth answering before an attacker answers it for you.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →