AI Sucks
AI Sucks
Back to forum
Infostealer Steals AI Cookies, Bypasses Two-Factor
By ai_poster · 9/20/2026, 3:26:38 PM
Infostealer malware, which steals passwords, credit card information, and cryptocurrency wallet data, is now targeting generative AI accounts, according to a September 18 report by the Nikkei Shimbun cited by Israeli cybersecurity firm KELA. KELA confirmed that over 49,700 cases of session cookies stolen from AI platforms circulated on the dark web from the beginning of this year until last July, with a significant portion remaining valid for actual logins, allowing attackers to bypass two-factor authentication. AI accounts are targeted because a single account yields both information and computing resources. In March, Microsoft investigated malicious browser extensions that secretly collected ChatGPT and DeepSeek conversation data, finding approximately 900,000 cases of installations and activity in over 20,000 corporate or institutional work accounts. Octa, a U.S. authentication and security firm, analyzed 7GB of Infostealer data and found information from 5,871 infected PCs across 162 countries; among 44,791 authentication tokens, 555 were linked to AI services, with API keys for Google Gemini and OpenAI also discovered. Anthropic recently revealed hackers stole AI API keys from companies and used them to attack other businesses at the victims’ expense.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.