Stolen AI session tokens are now being traded on Telegram marketplaces to bypass multi-factor authentication. According to an investigation by Okta, these hijacked credentials allow attackers to access premium accounts for services like ChatGPT and Claude without triggering security prompts .
The 7-gigabyte Telegram dump exposing 555 AI logins
An investigation by Okta's threat-intelligence team uncovered a massive data leak posted to a Telegram channel on August 2, 2026. The dataset, which totaled 7 gigabytes,contained 44,791 unique JSON Web Tokens (JWTs) and 2,937 JSON Web Encryption (JWE) records used for authentication.
The report from Okta's trheat-intelligence team highlights that 555 of these tokens were directly linked to major AI services.. These included login sessions for Google, Microsoft, Anthropic, Amazon, Character.ai, Cursor, Poe.com, Notion, Gamma, and Pika AI. Criminals specifically target these high-value tokens because they allow for seamless entry into paid subscriptions without the need for a password or a secondary authentication step.
How Camoufox and SeleniumBase mimic victim fingerprints
Criminal vendors are using highly sophisticated methods to sell "white-label" access to premium models, such as Anthropic's Opus 4.6-4.8 and Sonnet 4.6. Some of these black-market services are even operating under branded names like "Poison Claude."
To avoid detection, buyers are utilizing specialized automation tools to make their unauthorized access look legitimate. according to the Okta report, attackers use the open-source anti-deetect browser Camoufox and the SeleniumBase framework to load stolen session data. By reproducing the exact device fingerprint of the original victim, these criminals can bypass the fraud-detection systems implemented by AI providers.
The high cost of exposing legal and medical chat histories
The theft of these session tokens represents a significant shift in the cybercrime landscape, moving from simple credit card theft to the hijacking of intellectual property. While earlier attacks focused on financial data, modern criminals are increasingly targeting the credentials that provide access to advanced AI intelligence.
Individual users and professionals face severe risks, including the potential for attackers to drain subscription allowances or charge unauthorized expenses to a victim's bank card. More critically, an attacker gains a read-only view of a user's entire chat history and any uploaded files. For professionals in the legal or medical fields, this level of data exposure can result in a catastrophic breach of confidentiality and the loss of sensitive proprietary information.
Which specific users were among the 555 leaked sessions?
Several critical details remain unverified following the August 2, 2026, leak. While Okta identified the specific AI services compromised, the source does not clarify whether the 555 leaked tokens belong to individal consumers or high-level corporate accounts. Furthermore, it remains unknown how many of the 44,791 total tokens in the Telegram dump are currently being actively traded or if the breach has already been mitigated by the respective service providers.
Comments 0