Stolen AI Tokens Bypass MFA via Infostealer Logs — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Okta analyzed a 7 GB infostealer dump released on Telegram on August 2, 2026, containing data from 5,871 infected machines across 162 countries, harvested by malware families like Lumma Stealer and Vidar
- Jeremy Kirk of Okta said session tokens and API keys are prized because they can be replayed to bypass credential-based authentication, including MFA — calling them 'skeleton keys' that make abuse harder but not impossible to detect
- Of 44,791 unique JWTs found in the dump, 555 were likely tied to AI services like Google, Anthropic, Microsoft, Amazon, Cursor, and Poe.com, and 17.7% contained plaintext PII (name, phone, email) useful for phishing
- TruffleHog scanning unearthed 24 still-valid API keys for Google Gemini, OpenAI, Groq, and OpenRouter, enabling 'LLMjacking' — hijacking victim LLM accounts for espionage or to rack up token bills
- Okta flagged a Telegram vendor selling discounted access to Claude, Cursor, ChatGPT, and Gemini with 24x7 support and money-back guarantees, alongside a service called 'Poison Claude' claiming access to Anthropic's Opus 4.8, 4.7, 4.6, and Sonnet 4.6 models
- Google Threat Intelligence Group separately confirmed rising underground demand for AI accounts, and Mandiant documented one incident where an exposed GitHub PAT was used to deploy unauthorized AI infrastructure at the victim's expense
Why it matters: With 1,843 unexpired AI tokens circulating on August 2 and frontier model access growing more expensive, criminals have clear economic incentive to steal rather than pay — and MFA does nothing to stop them. Enterprise teams running LLM workloads via API now face credential theft risks that can translate directly into five-figure compute bills or stolen inference output.
Ask SkimNews




