Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Summary
Cybercriminals are using information stealers (malware that harvests data from infected computers) to steal session tokens and API keys for AI services, then selling them on underground forums so attackers can bypass login authentication and MFA (multi-factor authentication, extra security checks beyond passwords). A single stolen data dump contained thousands of unexpired tokens from services like Google, OpenAI, and Anthropic, along with personal information that could enable social engineering attacks.
Solution / Mitigation
Google has added support for Device Bound Session Credentials (DBSC) to Chrome to cryptographically link a session token to a device so that a stolen token cannot be used on another system. Additionally, session replay attacks may not work in scenarios where an organization uses IP allowlisting (a security feature that blocks all network traffic except for specific, approved IP addresses or ranges).
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
First tracked: September 9, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%