Threat Intelligence

Stolen AI Login Tokens Let Hackers Skip Passwords and MFA Entirely

The Hacker News · 10 Sept 2026
Key Takeaway Treat session tokens and API keys with the same care as passwords: rotate and revoke them regularly, monitor for unusual account activity, and ensure endpoint protection can detect infostealer malware before it harvests these credentials.

Security researchers at Okta have found that infostealer malware such as Lumma Stealer and Vidar is capturing more than just passwords. It is also grabbing session tokens, API keys and authentication tokens that can be replayed to log directly into accounts, effectively bypassing usernames, passwords and even multi-factor authentication (MFA).

Okta analysed a 7GB stealer log dump posted to Telegram in August 2026, which contained data from 5,871 infected machines across 162 countries. Within it were thousands of active authentication tokens tied to services including Google, Microsoft, Anthropic, Amazon, Notion, Cursor and other AI platforms. Of nearly 45,000 unique tokens examined, 555 were linked to AI service logins, and 1,843 tokens in total were still valid (unexpired) on the day the data was released.

The report also found that a large share of these tokens, about 17.7 percent, contained plaintext personal information such as names, phone numbers and email addresses. Because these tokens can be reused to access accounts without triggering normal login checks, detecting this kind of abuse is harder than spotting a stolen password being used.

infostealer malware MFA bypass AI security token theft credential theft
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.