September 9, 2026
Infostealer Logs Are Yielding Replayable AI Session Tokens and API Keys That Bypass MFA
Okta analyzed a 7 GB infostealer dump from 5,871 machines and found 1,843 unexpired JWTs and JWEs, including 555 tied to AI services such as Google, Anthropic, OpenAI, Cursor, and Character.ai, plus 24 still-valid API keys for Gemini, OpenAI, Groq, and OpenRouter. Replaying these tokens grants account access without a password or MFA, enabling LLMjacking and resource theft, and 17.7% of JWTs contained plaintext PII.
Stolen API keys and session tokens are the cheapest route into AI services, so token scoping, short expiry, and detection of replayed credentials on API endpoints are critical controls.
API Security
Read full story