Infostealer Malware Targeted AI Accounts

Hackers utilized stolen session cookies and malicious browser extensions to compromise AI services through July 2026.

Updated on Sept. 20, 2026 in Cybersecurity

Isometric editorial illustration of a single silicon wafer chip floating against a dark, minimalist background, representing cybersecurity infrastructure.
Cybercriminals harvested nearly 50,000 session cookies between January and July 2026, granting them unauthorized access to sensitive corporate AI accounts and computing resources. AI Illustration. Upload story photo >

Live Poll

Do you trust the security of your personal data when using generative AI tools?

Between January 2026 and July 2026, cybercriminals circulated over 49,700 stolen session cookies from AI platforms on dark web markets. This activity allowed unauthorized access to sensitive user documents and expensive computing resources.

Why it matters

AI accounts now function as critical repositories for internal business strategies and source code, making them prime targets for credential theft. Stolen API keys enable criminals to leverage these platforms for illicit activities at the expense of corporate and individual victims.

Security research identified 900,000 malicious browser extension installations that collected AI conversation data. Analysis of a 7GB Infostealer data set, spanning 5,871 infected PCs across 162 countries, revealed 555 authentication tokens linked specifically to AI services.

The players

Microsoft

A multinational technology corporation that provides enterprise security services and cloud computing solutions.

Anthropic

An AI research and safety company that develops large language models and other generative artificial intelligence tools.

Octa

A cybersecurity analytics firm that investigates data breaches and the distribution of stolen credentials online.

The details

Infostealer malware operates by infiltrating personal computers to extract stored passwords, login credentials, and session cookies from web browsers. By harvesting these files, attackers successfully bypass traditional login barriers and two-factor authentication to take control of active AI accounts.

Timeline

  1. January 2026 to July 2026: More than 49,700 AI session cookies were traded on dark web markets.

  2. March 2026: Microsoft detected 900,000 malicious browser extension installations collecting AI data.

The Tech Race

This activity follows the established trend of Infostealer malware shifting its primary target from simple financial credentials to high-value AI accounts. As these platforms evolve into agents capable of executing complex human tasks, they replace legacy systems as the most lucrative targets for cybercriminals.

Users can mitigate these risks by removing unused browser extensions and enabling hardware-based security keys to protect their AI account access. Businesses should implement stricter monitoring for unauthorized API usage to prevent criminals from exploiting their paid computing resources.

The takeaway

The evolution of AI into a tool for executing autonomous tasks makes account security as critical as password protection for financial institutions. Users should treat AI accounts as sensitive business assets and maintain rigorous digital hygiene to prevent unauthorized access.

Further reading

Learn more about evolving digital threats in the Cybersecurity section.

Live Poll

Do you trust the security of your personal data when using generative AI tools?