Threat · curated 9 Sep 2026
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
First reported thehackernews.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Replayable AI session tokens and API keys let attackers bypass MFA and directly access enterprise AI accounts and model-provider tools, turning stolen credentials into persistent access to AI systems.
Cybercriminals are harvesting AI account session tokens and API keys via information stealers like Lumma Stealer and Vidar, then selling them in stealer logs to create 'stolen keys' that grant illicit access to tools from model providers including Google and Anthropic. According to Okta threat intelligence cited by The Hacker News, these session tokens and API keys can be replayed to bypass credential-based authentication and MFA.