NewsTradingSentimentCalendarCommunityBriefing
Tech

Stolen AI Tokens Bypass Security Checks

By Tech Desk · 2026-09-09 · 2 min read
A digital padlock with a broken keyhole
Illustration: Tradingbird

Cybercriminals are exploiting leaked AI service tokens to bypass multi-factor authentication, according to a new security report.

Cybercriminals are increasingly targeting artificial intelligence accounts by harvesting valid authentication tokens from compromised computers. These stolen digital keys allow attackers to bypass standard login procedures and multi-factor authentication, effectively logging into major AI services without needing a password. This technique, known as session replay, grants immediate access to tools from providers like Google and Anthropic.

The risk stems from common malware used to steal data from infected systems. When these programs capture active session tokens or API keys, they create a shortcut for hackers. Instead of cracking passwords, attackers simply reuse the captured credentials to impersonate legitimate users. This method has turned AI account access into a commodity sold on underground forums.

Massive Leak Reveals Stolen Access

A recent analysis of a seven-gigabyte data dump shared on a messaging platform highlighted the scale of the problem. The dataset contained information from nearly six thousand infected machines across 162 countries. Security researchers identified thousands of unexpired tokens linked to popular AI and productivity services. The sheer volume of valid credentials suggests that many users remain unaware their access rights have been compromised.

The report, shared with The Hacker News, noted that a significant portion of these tokens included personal details like names and email addresses. This data does not expire, providing attackers with a permanent link to user identities. Such information is particularly valuable for crafting targeted phishing emails or social engineering attacks, making it harder for victims to recognize fraudulent communications.

Attackers Exploit Valid Digital Keys

The core issue is that many AI services trust active session tokens as proof of identity. As long as a token is valid and not expired, an attacker can use it to operate within the account. This bypasses the need for secondary verification methods like text message codes or authenticator apps. The result is that multi-factor authentication, a cornerstone of modern security, becomes irrelevant if the initial session is already established.

Researchers also found valid API keys for several AI platforms. These keys allow direct programmatic access to the services, enabling hackers to use the victim's resources for their own projects. They can rack up significant usage bills for the account holder or sell access to other criminals. This abuse mirrors cryptocurrency mining scams, where victims bear the cost of unauthorized resource consumption.

Security Measures Limit But Do Not Eliminate Risk

Some security features can mitigate this threat, but they are not universally applied. Organizations that restrict network access to specific IP addresses can block replay attacks from unauthorized locations. Additionally, some browser technologies now link session tokens to specific devices, preventing stolen keys from being used on different hardware.

However, these protections are not yet standard for all users or services. Most individuals do not manage IP allowlists, and device-bound credentials are still being rolled out. Until these measures become widespread and mandatory, the threat of token replay remains a significant gap in AI account security. Users must remain vigilant about their digital hygiene and promptly revoke active sessions when suspicious activity is detected.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories