Back to News
Cybersecurity

Cybercriminals Exploit AI Tokens for Unauthorized Access, Bypassing MFA

New findings reveal cybercriminals are using infostealer logs to create stolen AI tokens, enabling access to sensitive tools and bypassing multi-factor authentication.

Recent investigations reveal that cybercriminals are leveraging information stealer logs to generate 'stolen keys' that facilitate unauthorized access to artificial intelligence tools from major providers such as Google and Anthropic. Tools like Lumma Stealer and Vidar are capable of harvesting diverse types of sensitive data, including user credentials, session tokens, and API keys, which can be exploited to bypass multi-factor authentication (MFA) protections.

For businesses, this development underscores the critical need for enhanced security measures beyond traditional MFA solutions. With cybercriminals increasingly capable of circumventing these safeguards, organizations must consider adopting more robust identity verification methods, such as biometric authentication or adaptive risk-based security protocols. This trend is particularly concerning as it highlights the vulnerability of AI systems to sophisticated attacks, necessitating a reassessment of current cybersecurity practices to protect sensitive intellectual property and maintain trust in AI technologies.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html)*