The question
It's not a weird thing to check — it's become one of the fastest-growing categories of account theft this year. Researchers are tracking dark-web marketplaces, some running on Telegram with 24/7 customer support and money-back guarantees, that sell stolen access to Claude, ChatGPT, Gemini, and Cursor accounts at up to 97% off retail. More than 80,000 organizations have had AI logins stolen so far.
What we told them
The mechanism is the part most people miss: this isn't password-guessing. Infostealer malware on an employee's device — often from a pirated app, a fake browser extension, or a compromised download — grabs the active session token for whatever's logged in on that machine. That token is the thing that proves you're already authenticated. Whoever buys it gets in without ever touching your password or your MFA prompt, because from the service's point of view, that session already passed both.
That's why this is easy to miss. There's no failed-login alert, no "new device" email most people would notice, because nothing about the login looks new — it's a replay of a session that was already valid. The seller isn't breaking in; they're walking through a door someone else already opened and forgot to close.
Here's what we had them check:
- Pull the usage/activity log for every paid AI seat. Claude, ChatGPT Team/Enterprise, and most paid tiers log session activity, IP ranges, and usage volume — look for access from unfamiliar locations or usage spikes that don't match anyone's actual work pattern.
- Treat AI accounts like you treat email and banking — not like a free tool. If the account isn't inside your SSO/identity provider, it's a standalone credential sitting outside your normal monitoring.
- Rotate sessions, not just passwords. A password reset doesn't necessarily kill an already-active stolen session — explicitly sign out all active sessions from the account's security settings after any suspected exposure.
- Check employee devices for infostealer infections, not just the AI account itself — the theft happens upstream, on the machine, well before the account is ever touched.
A stolen AI account doesn't look stolen — it looks like a normal login, because it is one. If your team's AI seats aren't inside your identity provider and nobody's ever looked at the usage logs, you don't actually know who's using them right now.