When your employees use AI tools you haven’t approved, they create accounts you can’t see, secure, or shut down, each with a chat history full of your business data.
New research published by SOCRadar(หน้าต่างใหม่) found that more than 80,000 organizations globally have had their employee AI logins appear in infostealer logs. Infostealers are a type of malware that collect passwords, session cookies, financial and personal, and chat logs from infected devices and send them back to the attacker. That data makes phishing or ransomware attacks far more effective.
SOCRadar’s research makes the case that AI session credentials are extremely valuable to attackers. A single AI login can unlock “a searchable archive, an execution engine, a billable resource and an identity — and the stolen session hands over all of them without a password prompt,” as the report puts it. To a criminal, this is a goldmine.
The concerning takeaway for businesses adopting AI today is that these credentials aren’t leaking because of the security of the AI platforms themselves. They’re leaking because of two less obvious factors: the sheer number of employees using AI tools, and the growing share of that use happening outside IT’s control.
What does the research reveal?
Overall, the report identifies that AI-service credentials are appearing in infostealer logs in significant numbers. The key takeaways are:
- More than 1,000,000 records connected to AI services were revealed across 80,000 unique corporate domains.
- From that set, it verified a cross-section of 482 organizations were identified as major enterprises, mostly in North America — 68% of them are billion-dollar organizations.
- Technology firms are the largest group, at 144 companies and 40% of records.
- Those 482 organizations account for 5,434 log records tied to 1,500 corporate email addresses.
- The exposure is recent: 295 organizations of that 482 have had infostealer logs records surfaced in the last 90 days.
- ChatGPT appeared in logs for 358 of 482 organizations and in about 90% of records, followed by Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs.
That last stat raises an obvious question: why ChatGPT? SOCRadar’s explanation has less to do with the tools than with how employees are using them.
Shadow AI is creating risk
Shadow AI is any AI tool employees use without their company’s approval or knowledge. Employees bring shadow AI into their business networks when their corporate accounts are limited, or the tools they have aren’t effective for the task they’re carrying out.
A researcher at SOCRadar comments:
“We read the near-total dominance of ChatGPT as a shadow-AI signal, not a verdict on any vendor’s security. ChatGPT’s first-mover advantage means it likely has an order of magnitude more corporate users — many of them signing up with a work email on a personal device, outside any policy. That is exactly the population infostealers scrape. Claude and Gemini barely appear because far fewer employees have quietly created accounts on them yet — not because those credentials are safer to steal. As enterprise adoption of other assistants catches up, we expect this chart to even out.”
So, ChatGPT’s lack of end-to-end encryption for chats isn’t the culprit for the tool’s prominence in the infostealer logs. ChatGPT tops the list because it has the most corporate users, and because so many of them are using it outside company policy.
Employees may also attempt to evade restrictive IT policies that prevent them from taking the fastest or easiest option, but they may also genuinely not know what policies or restrictions are in place. Your business can’t protect accounts it doesn’t know exists, or queries made outside a business account.
Regardless of intention, when workers combine personal and business AI use, they run afoul of your company’s data use policies and land under OpenAI’s consumer terms instead.
Open AI says it doesn’t train on business data, but when an employee operates outside business acceptable use guidelines or uses a personal account for business purposes, they lose control of that data: their chat archive (including sensitive business data or personally identifiable information (PII)) is collected, logged, and potentially used to train OpenAI’s models.
OpenAI may share business data with third parties or via app integrations: in 2025, hackers were able to breach an OpenAI vendor and steal business customer data including names, emails, locations, and system details. As a US company, it can also be compelled to share data with the US government under the Patriot Act or FISA, even without notifying you.
How to protect your business from shadow AI
Shadow AI happens when employees don’t have a tool they’re allowed to use, or a good enough one. So the first fix is to give them one.
Lumo, built by Proton, gives your team a sanctioned alternative to personal accounts and keeps business data stays private. It doesn’t keep logs or train on business or personal conversations. All saved chat history is protected zero-access encryption, so no-one (not even Proton) can read it.
Encryption protects stored data, but it can’t help if an attacker is already on the employee’s device. To close that gap, take these steps:
- Find the accounts you don’t know about. Check whether your company’s domains already appear in stealer logs and ask teams which AI tools they actually use.
- Treat a stealer-log hit as an endpoint incident. If an employee’s credentials turn up in a log, the device is infected. Resetting the password alone leaves the attacker’s stolen session live, so revoke active sessions and clean or replace the machine.
- Put every sanctioned AI tool behind SSO with short-lived sessions. A stolen cookie that expires in hours is worth far less than one that lasts weeks.
- Lock down API keys. Scope them to what they need, rotate them regularly, and never store them in notes apps or shared docs.
- Keep work off unmanaged devices. If staff need AI on personal devices, require them to sign in through company accounts you can monitor and revoke.
- Set up dark web monitoring. It alerts you when employee credentials appear in leaks, so you can act before an attacker does.
Your employees will use AI either way. Offer them a ChatGPT alternative that keeps no logs, never trains on your data, and locks every saved chat behind encryption not even Proton can open.






