Stolen AI Session Tokens Bypass MFA in Infostealer Campaign
Threat actors are using stolen session tokens and API keys from infostealer logs to bypass multi-factor authentication and hijack AI service accounts from

Cybercriminals are hijacking artificial intelligence accounts using stolen authentication tokens that bypass password and multi-factor authentication (MFA) checks. This emerging attack vector exploits data harvested by information-stealing malware like Lumma Stealer and Vidar.
Jeremy Kirk, director of threat intelligence at Okta, explained the core risk. "Session tokens and API keys are sought specifically by threat actors because it is often possible to replay those secrets and bypass credential-based authentication," he said. "Once successfully replayed, a threat actor is effectively logged in to an LLM service without actually logging in."
The Scale of the Stolen Token Cache
Okta analyzed a 7 GB infostealer data dump posted to a Telegram channel on August 2, 2026. The cache contained information from 5,871 infected machines across 162 countries. Within this data, researchers found thousands of unexpired authentication tokens for services including Google, Microsoft, Anthropic, Amazon, and various AI platforms.
The dataset held 44,791 unique JSON web tokens (JWTs), with 555 likely tied to AI service authentication. A valid JWT can grant direct account access, sidestepping the need for usernames, passwords, and MFA. Okta also identified 2,937 encrypted JWE data structures, most set by OpenAI. While encrypted, these tokens can still be replayed by an attacker for access if they have not expired.
On the day of the dump's release, it contained 1,843 unexpired JWTs and JWEs. A concerning 17.7% of the 44,791 JWTs included plaintext personally identifiable information like names, phone numbers, or email addresses. "This is another problematic aspect since that information does not expire or disappear, and it directly links a user with a specific service, which could be useful for social engineering attempts or phishing," Kirk noted.
From Stolen Keys to "LLMjacking"
Beyond session tokens, the analysis using TruffleHog uncovered 24 still-valid API keys for AI-related services. Attackers can weaponize these keys for espionage, extortion, or resource theft, running up victims' AI token bills. This abuse of API keys to gain unauthorized access to large language models is termed "LLMjacking." The technique parallels cryptojacking campaigns, where attackers secretly use a system's resources and pass the compute costs to the victim.
The cybercrime ecosystem has adapted to monetize this new data stream. Okta flagged Telegram posts where vendors sell discounted access to AI services like Claude, Cursor, ChatGPT, and Gemini, complete with support and money-back guarantees. Another service, Poison Claude, advertises access to specific Anthropic models.
Tools and Techniques for Token Replay
Accessing accounts with stolen session data requires specific tooling designed to evade security controls. "So-called 'anti-detect' browsers have features designed to use stolen authentication data and avoid security controls," Okta stated. Open-source tools like the Camoufox browser or SeleniumBase can easily load stolen sessionStorage and localStorage data from a file. These tools often allow proxy configuration, helping attackers bypass "impossible travel" detections that would normally flag logins from geographically disparate locations.
Google's Threat Intelligence Group has observed a surge in this activity. "The cost of premium model access and high-performance compute is one of the primary barriers for threat actors seeking to operationalize AI," the group said. This economic incentive has led to increased targeting and sale of AI accounts and a rise in intrusions aimed at hijacking enterprise cloud compute resources. In one incident handled by Google's Mandiant, an attacker used an exposed GitHub Personal Access Token to deploy unauthorized AI infrastructure in a victim's cloud environment.
Potential Defenses and Persistent Risks
Certain security measures can mitigate session replay attacks. Organizations using IP allowlisting, which blocks traffic from unapproved IP addresses, can prevent some of these attacks. Google has also implemented Device Bound Session Credentials in Chrome to cryptographically tie a session token to a specific device, rendering a stolen token useless on another system.
Experts recommend securing AI system access by monitoring for session token reuse, scoping API key permissions, and using OAuth 2.0 flows with short-lived tokens. However, as strong authentication like passkeys makes traditional credential theft harder, stolen session tokens and API keys remain a potent threat. "As frontier model access grows more expensive, the incentive to steal rather than pay for it grows too," Kirk concluded. Posts on cybercrime forums show specific buyer demand for credentials to Claude and Gemini, alongside autonomous coding tools like Cursor Pro and Devin.





