Stolen AI Tokens in Infostealer Logs Enable MFA Bypass Globally
AI-generated from multiple sources. Verify before acting on this reporting.
LONDON (AP) — Cybercriminals are exploiting stolen session tokens and API keys found in infostealer logs to bypass multi-factor authentication and gain unauthorized access to artificial intelligence services across 162 countries. The discovery, confirmed on Sept. 9, 2026, reveals a critical vulnerability where replayable credentials allow attackers to impersonate legitimate users without triggering standard security alerts.
The compromised data includes active session tokens that remain valid until their natural expiration or manual revocation by the user. Unlike traditional password theft, these tokens grant immediate access to AI platforms, effectively rendering multi-factor authentication controls useless for the duration of the session. Threat actors are leveraging this capability to monetize stolen access, running unauthorized computational tasks, generating proprietary content, and staging follow-on attacks against corporate networks.
The scope of the breach is global, with evidence of compromised credentials originating from users in 162 nations. The attack vector relies on infostealer malware previously installed on victim devices, which silently harvests browser cookies, local storage data, and active session tokens. Once exfiltrated, these logs are sold or traded on underground forums, where buyers can immediately deploy the stolen keys to access high-value AI models.
Security experts warn that the ability to bypass MFA represents a significant escalation in the sophistication of credential-based attacks. By using valid session tokens, attackers do not need to crack encryption or solve complex authentication challenges. They simply present the stolen token to the service provider, which accepts it as proof of a verified login. This method allows for rapid, automated exploitation of AI services before victims or administrators detect the anomaly.
The primary motivation behind this campaign is financial gain and strategic advantage. Monetization occurs through the resale of access credentials or the direct use of stolen compute resources to train models or generate data. Additionally, the unauthorized access serves as a foothold for deeper network infiltration, allowing threat actors to pivot from AI platforms to internal corporate systems.
As organizations scramble to address the exposure, questions remain regarding the full extent of the damage and the number of affected users. It is unclear how many sessions were compromised before detection or whether the stolen tokens have been used to access sensitive government or healthcare data. Furthermore, the industry faces uncertainty over how quickly service providers can implement technical controls to invalidate these replayable tokens without disrupting legitimate user workflows.
The incident highlights a growing blind spot in current cybersecurity defenses, where the focus on password protection has left session management vulnerable. Until new standards are adopted to detect and neutralize stolen tokens, the risk of widespread unauthorized access to AI infrastructure remains high.