← Back to blog

Stolen AI Tokens Bypass MFA, Exposing Enterprise Risk

Cybercriminals are using infostealer malware to harvest AI platform session tokens, enabling unauthorized access even when MFA is enabled. These replayable tokens bypass traditional authentication safeguards.

TL;DR

  • Infostealers like Lumma and Vidar extract AI session tokens from browsers
  • Tokens allow persistent access to AI platforms without triggering MFA
  • Attackers exploit harvested credentials across Google, Anthropic, and more
  • Traditional security controls fail to detect token-based account takeovers
  • Organizations should monitor for abnormal API usage and enforce just-in-time access

Threat actors are increasingly targeting artificial intelligence platforms by stealing session tokens through common infostealer malware. These stolen tokens act as persistent keys, granting unauthorized access to AI services without requiring passwords or triggering multi-factor authentication (MFA). This emerging attack vector poses significant risk to enterprises relying on AI tools from major providers.

Security researchers have identified that popular infostealers such as Lumma Stealer and Vidar are now configured to extract API keys and session cookies from browsers. Once harvested, these tokens enable attackers to impersonate legitimate users and interact with AI models indefinitely, effectively bypassing conventional authentication mechanisms.

How Token Theft Works

  • Infostealer malware scans browser storage for API keys and session tokens associated with AI platforms
  • Harvested tokens retain validity even after the original user changes their password
  • Attackers can reuse these tokens programmatically to access AI services without detection
  • Unlike phishing, this method doesn't require user interaction or credential disclosure

Enterprise Defense Strategies

  • Implement short-lived tokens with automatic rotation policies for all AI service integrations
  • Monitor for unusual API activity patterns that deviate from normal user behavior
  • Enforce just-in-time access controls and ephemeral sessions for sensitive AI platforms
  • Deploy endpoint detection solutions capable of identifying infostealer behaviors
  • Conduct regular audits of stored credentials and revoke unused or stale tokens

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.