Stolen AI session tokens let thieves skip the login step

Okta found thousands of live AI session tokens in a stealer log, letting thieves replay their way into paid tools.

CSBadmin
2 Min Read

Okta warns that criminals are taking over AI accounts using secrets lifted by information stealers.

Stealers like Lumma and Vidar grab credentials, session tokens, and API keys. Those logs are resold on underground forums, and the tokens are prized because they can often be replayed to skip a sign-in entirely.

Okta’s Jeremy Kirk explained the payoff. A replayed token amounts to being signed in to a model service without ever signing in, and the trick also skips usernames, passwords, and MFA.

Okta dug into a 7 GB dump posted to Telegram on August 2. It held data from 5,871 infected machines in 162 countries. A scan with TruffleHog found 24 still-valid API keys for services such as Google Gemini, OpenAI, Groq, and OpenRouter. Of 44,791 unique JSON web tokens, 555 looked tied to AI services, and 1,843 tokens and encrypted tokens were unexpired the day the dump appeared. Roughly 17.7 percent carried plaintext personal data.

The practice is known as LLMjacking, lending or reselling stolen model access. One Telegram seller offered discounted Claude, Cursor, ChatGPT, and Gemini access with round-the-clock support and refunds; another pushed Anthropic’s Opus models.

Okta’s guidance: watch for token reuse, keep API keys tightly scoped, and prefer short-lived OAuth tokens that expire quickly if stolen.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.