DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

Infostealer Logs Expose AI Session Tokens That Bypass MFA

Forensic Summary

Cybercriminals are harvesting JWT session tokens and API keys from infostealer logs to replay authentication against major AI platforms including OpenAI, Anthropic, and Google, effectively bypassing MFA entirely. Analysis of a 7 GB stealer dump revealed 1,843 unexpired tokens targeting AI services on the day of release, with 17.7% of all JWTs containing plaintext PII usable for follow-on social engineering. This attack pattern is particularly dangerous for AI platforms because stolen tokens grant full account access without triggering standard credential-based security controls.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/infostealer-logs-expose-ai-session-tokens-that-bypass-mfa/

Top comments (0)