Infostealer Logs Expose AI Session Tokens That Bypass MFA
Cybercriminals are harvesting JWT session tokens and API keys from infostealer logs to replay authentication against major AI platforms including OpenAI, Anthropic, and Google, effectively bypassing MFA entirely. Analysis of a 7 GB stealer dump revealed 1,843 unexpired tokens targeting AI services on the day of release, with 17.7% of all JWTs containing plaintext PII usable for follow-on social engineering. This attack pattern is particularly dangerous for AI platforms because stolen tokens grant full account access without triggering standard credential-based security controls.