The breach story of the past decade was about exfiltration: intruders broke in, copied a database, and left. The story emerging from the current reporting is different. Attackers are stealing AI credentials and sessions, then using the victim's own access and budget to do the work. The theft is often the beginning of the loss, not the end of it.
The Market for Stolen AI Logins
The clearest evidence of the shift comes from BleepingComputer, which reported on SOCRadar research finding that infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains. That is not a list of exposed passwords in the abstract. It is a working inventory of entry points into the AI tools that employees and, increasingly, automated agents use every day. SOCRadar's framing places the risk on a spectrum running from stolen conversations to LLMjacking, which is the practice of running up an organization's AI bill using its own compromised access.
Google analysts, as reported by ZDNET, have separately warned that stolen AI credentials are being sold underground, with businesses footing the bill. Two independent research efforts are describing the same supply chain: infostealers collect credentials, a secondary market prices and sells them, and buyers monetize the access. The victims frequently do not learn about it from an alert. They learn about it from an invoice.
Why AI Credentials Are Different From Other Credentials
A stolen email password is bad. A stolen AI session or API credential is a different category of problem, for three reasons that the reporting makes plain.
First, the credential often carries spending authority. LLMjacking, as ZDNET describes it, converts a stolen credential directly into cost borne by the victim. The attacker does not need to monetize stolen data on a separate market. The access itself is the revenue.
Second, the credential frequently carries context. BleepingComputer's account of the SOCRadar findings notes that exposed sessions create risks that include stolen conversations. A session is not just a key. It can be an open window into prior prompts, uploaded documents and whatever institutional knowledge passed through the tool.
Third, AI credentials are proliferating faster than traditional ones because adoption is being driven by individual employees. The term SOCRadar uses, shadow AI, captures the pattern: tools adopted outside central procurement and outside central identity management, which means they are also outside the monitoring that would normally catch a credential stuffing or resale event. The population of credentials worth stealing is growing, and the controls around much of that population are thin.
The Agent Problem Compounding the Breach Problem
The third strand of recent reporting makes the first two harder to contain. BleepingComputer also covered Token Security's argument that AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security's point is that agent identities create security gaps the current audit framework was not designed to see.
Put the two findings together and the breach perimeter changes shape. An attacker who steals a credential is no longer impersonating one employee doing one task at human speed and human hours. If that credential is bound to an agent, the attacker may inherit an automated actor with standing permissions, operating at machine speed, whose activity looks like legitimate business activity to controls calibrated for people. The stolen session BleepingComputer reported on and the agent identity Token Security describes are the same attack surface viewed from two angles.





