Hackers are using infostealer malware to steal login credentials and API keys from major AI platforms such as OpenAI, Anthropic, and Google. These stolen accesses are resold on underground markets at 40 to 60 percent discounts off retail pricing. CrowdStrike’s report documents an 89 percent increase in AI-related adversary activities between July 2025 and June 2026. Okta’s analysis of a 7 GB dump of infostealer logs found hundreds of unexpired tokens tied to AI services. In September 2026, autonomous AI-agent campaigns compromised infrastructure across 395 organizations in 48 countries.
Source: Read the original article

