Skip to content
Security & Trust

SOCRadar: ChatGPT's lead in stolen AI logins at 482 firms hints at shadow AI

The data cannot say which accounts were approved, so the first job is an inventory of what employees use.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
SOCRadar: ChatGPT's lead in stolen AI logins at 482 firms hints at shadow AI

AI-generated image for WebPulse. About our images

Key finding

Companies with a captured ChatGPT or OpenAI session: 358 of 482 (Source: SOCRadar AI Identity Exposure Report, via BleepingComputer (September 28, 2026))

A stealer log can confirm that an employee's AI login was captured. It cannot say whether the company had approved that account. That gap sits at the center of SOCRadar's AI Identity Exposure Report, covered by BleepingComputer on September 28, 2026, and it shapes what a budget-holder should do first. WebPulse's reading is that stolen AI logins raise an inventory question before a tooling question. Whether many of these accounts were sanctioned or few, a company needs its own count of which ones exist.

What the dataset shows

SOCRadar's starting pool covered upward of 80,000 company domains and over a million infostealer entries that mention AI services. From it, the firm chose 482 established enterprises across 36 countries and eight sectors. Across those firms the tally is 5,434 stealer-log entries covering 1,500 unique work email addresses, and 295 of the companies were seen in the past 90 days.

358 of 482
Companies with a captured ChatGPT or OpenAI session
Source: SOCRadar AI Identity Exposure Report, via BleepingComputer (September 28, 2026)

Scope matters. This is a security vendor's analysis of a selected group of large enterprises, not a random sample. It counts records in stealer logs, and the source does not say how many led to misuse.

What the ChatGPT skew does and does not show

The 358 companies with a captured ChatGPT or OpenAI session account for roughly 90% of all records in the study. Other platforms, among them Zapier, Notion and Hugging Face, trail by a wide margin.

SOCRadar attributes the pattern to timing rather than vendor security. ChatGPT's first-mover advantage means far more employees signed up with a work email on a personal device, which is the population infostealers collect from. SOCRadar reads the dominance as a "shadow-AI signal" and expects the chart to even out as other assistants gain adoption.

That is a reading, not a measurement. The 90% describes how records are spread across platforms. It cannot show how much of the underlying use was sanctioned, and the dataset does not say how many of the accounts the companies had approved. Some may well have been.

Claude and Gemini are absent from the leading ranks, which does not put them out of reach. BleepingComputer's own commentary points to Anthropic's late-August response to infostealer-driven Claude session hijacking, when the company signed users out, removed saved payment methods and refunded charges it judged unauthorized. It adds that Claude has a smaller corporate footprint to collect from today. The lesson it draws is that exposure tracks where users are, not which assistant is chosen.

Why an inventory comes first

This section is WebPulse's inference from SOCRadar's reading. If the reading holds for even part of the dataset, some accounts sit outside company records, and controls attach to what is recorded. If it does not hold for a given company, the accounts were approved, and the company still needs to know their session, key and sign-on status. Either way, discovery precedes other spending, and someone has to own it.

The article's guidance draws a line around single sign-on. It removes the stored password, yet a session cookie that is already live stays usable, and accounts opened before a sign-on mandate fall outside it.

What a captured AI account holds

The article contrasts an ordinary app credential, which opens one door, with an AI account that bundles a searchable record of past work, the means to run tasks, spendable capacity and the user's identity. It notes that prompts often carry internal code, customer information, agreements and plans not yet public. Someone replaying a captured session reaches that history without entering any internal system.

Okta's Jeremy Kirk is cited on why attackers want tokens and keys: both can be reused to sidestep credential checks. A password change does not, by itself, end a session an attacker already holds.

Automation tools raise the stakes. The article notes that Zapier holds long-lived OAuth permissions into CRM, email and storage, so a hijacked session could set up a scheduled workflow that moves data out. Separately, API keys stored in notes or settings pages can be used at the owner's expense or resold. By sector, exposure to agent and automation tools clusters in healthcare, financial services and technology.

Technology and internet-services firms form the largest group at 144 companies, and the article notes that these firms hold data for many downstream clients.

40%
Share of all records held by technology and internet-services firms (144 companies)
Source: SOCRadar AI Identity Exposure Report, via BleepingComputer (September 28, 2026)

Entry is undemanding, per the article. One employee's unmanaged laptop with a saved ChatGPT password, plus off-the-shelf infostealer malware advertised on Telegram since 2022, is enough. Earlier shadow-IT programs taught a related lesson: what a team cannot see, it cannot rotate or revoke.

295
Of the 482 enterprises, those that surfaced in the last 90 days
Source: SOCRadar AI Identity Exposure Report, via BleepingComputer (September 28, 2026)

Questions to put to your team

Who owns the inventory of AI accounts: security, IT or procurement? If no one does, assigning an owner is the first decision. Before buying anything, run a lookup to see whether your company's email domains already appear in stealer-log data. SOCRadar offers a free tool for this, and because it is a vendor product, treat the output as a lead to validate. Then ask which of the accounts you find were approved. The dataset cannot answer that for you.

Does an employee appearing in a stealer log open an endpoint incident or a password-reset ticket? The article recommends the former. Is anyone alerted when a session changes country or device fingerprint mid-life?

How many AI accounts predate your sign-on policy? That count sizes work the policy cannot do for you. For the accounts it does cover, are sessions short-lived, with refresh-token rotation?

Are API keys scoped, capped and rotated, with alerts for unfamiliar networks or odd hours, the pattern the article associates with LLMjacking? A cap sets a ceiling on what a stolen key can bill to your budget.

Stealer logs hold a record of employee AI accounts that someone else keeps. The first job is to hold your own.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: BleepingComputer.

Share this insight