SOCRadar says infostealer records tied to AI services exposed employee credentials and sessions across more than 80,000 corporate domains. Its AI Identity Exposure Report examined over one million records, then narrowed the analysis to 482 established enterprises.
Among those companies, 68% were billion-dollar organizations spanning 36 countries and eight sectors. The dataset contained 5,434 stealer-log records linked to 1,500 distinct corporate email addresses; 295 companies appeared in records from the prior 90 days.
ChatGPT or OpenAI sessions appeared for 358 of the 482 companies, which accounted for roughly 90% of the records in the study. SOCRadar interprets that concentration as a possible sign of shadow AI adoption, saying employees may have registered with work emails on personal devices. The report says Claude and Gemini did not rank among the leading platforms, while noting that Anthropic responded to a late-August Claude-session hijacking incident by signing users out, removing saved payment methods and refunding charges it identified as unauthorized.
The report describes stolen AI sessions as a route to saved conversations, billable accounts and connected services. It also says technology and internet-services firms formed the largest sector group, with 144 companies and 40% of all records. SOCRadar recommends treating AI platforms as part of the organization’s identity and code-security landscape. These findings and interpretations are attributed to SOCRadar.
Comments
0No comments yet. Be the first to comment.