The tokens are pulled from infostealer malware campaigns, and the mechanic that makes them so valuable is also what makes them so dangerous: they bypass your password and your multi-factor authentication entirely. If a criminal has a valid session token from your machine, they can walk straight into your paid AI account without triggering a single login prompt. This is not a hypothetical. There are marketplaces already selling access, and one of them is helpfully named Poison Claude.
What Okta Actually Found
Okta’s threat intelligence team analyzed a 7 GB infostealer log dump that was published on a Telegram channel on August 2, 2026. The data was pulled from 5,871 infected machines across 162 countries. Inside that dump, Okta counted 44,791 unique JSON Web Tokens (JWTs), and a subset of them stood out as particularly valuable: 555 tokens directly tied to AI service authentication for Google, Microsoft, Anthropic, Amazon, Character.ai, Cursor, Poe.com, Notion, Gamma, and Pika AI. The team also identified an additional 2,937 JSON Web Encryption structures used for authentication.
The infostealer families involved in the campaign include well-documented commodity malware like Lumma Stealer and Vidar. These strains typically arrive through phishing emails, fake software installers, and malicious browser extensions, and once they land on a machine, they sweep every browser session for credentials, cookies, and cached tokens. Historically the market for that data has been credit cards and email logins. What has changed is that AI account tokens are now on the shopping list too.
How Session Tokens Bypass MFA in the First Place
Multi-factor authentication is designed to defend against stolen passwords. It works because a password alone is not enough to access an account: the second factor, whether that is an SMS code, an authenticator app, or a hardware key, has to be produced fresh at login. Session tokens sit downstream of that entire process. Once you have successfully logged in, the service issues you a token that represents your authenticated session, and every subsequent request the app makes uses that token. If someone else copies the token before it expires, they inherit your authenticated state without ever having to reproduce the login flow.
Jeremy Kirk, director of threat intelligence at Okta, put it directly: session tokens and API keys are prized specifically because they can be replayed to bypass credential-based authentication. The password is irrelevant. The MFA prompt is irrelevant. The token itself is the whole credential.
The New Marketplace for Stolen AI Accounts
What makes this story different from every other infostealer report is the professionalism of the resale market. Okta flagged Telegram listings from vendors offering discounted access to Claude, Cursor, ChatGPT, and Gemini, complete with 24/7 support and money-back guarantees. One service, branded as Poison Claude, specifically advertises access to Anthropic’s newer Opus 4.6, 4.7, and 4.8 models, along with Sonnet 4.6. The vendors have refined the customer experience to match the mainstream SaaS market they’re stealing from.
Actually using a stolen token requires more than just the token itself. Buyers deploy specialized tools like Camoufox, an open-source anti-detect browser, and SeleniumBase, an automation framework, to load stolen session data from browser storage and mimic the original victim’s device fingerprint closely enough to avoid triggering the AI provider’s fraud detection. The infrastructure to abuse these tokens at scale is now commoditized, which is why Okta expects the market for stolen AI credentials to keep expanding as long as the underlying infostealer economy stays profitable.
What This Means for Anyone With an AI Account
The immediate risk to individual users breaks into two categories. First, if your machine gets hit by an infostealer, your paid AI subscriptions become someone else’s product. The attacker consumes your usage quota, potentially runs their own workloads through your billing, and generally leaves you with a suspended account and a suspicious payment method that the provider will flag or delete. Anthropic has already been logging out affected Claude users and removing saved payment methods when it detects abnormal activity, which is the polite version of “your card was about to get charged for someone else’s LLM habit.”
Second, and less visible, a stolen session token can give the attacker access to your conversation history and any files you have uploaded to the service. For anyone using AI tools for work, that is not a small exposure. Legal drafts, sensitive analytics, product roadmaps, medical notes, code, personal correspondence: all of it lives in those chat histories, and none of it is protected by an MFA prompt once the token is out.
Where NordVPN Fits, and What It Can Actually Block
Let’s be direct about the limits. NordVPN cannot undo a token that has already been stolen from a compromised machine. What it can do, and where it earns its place in this specific attack chain, is block the initial infection vector. Infostealers are delivered through phishing links, fake installer domains, and malicious browser extensions, and Threat Protection Pro, included in NordVPN’s Advanced and Ultra plans, maintains continuously updated lists of those domains and refuses the connection at the network layer.
The Dark Web Monitor feature covers the aftermath. When your credentials or identifiers surface in a new dump, whether that is a stolen password, an email address in a breach corpus, or authentication data in a stealer log, the monitor alerts you so you can rotate your logins before someone gets around to reselling them on Telegram. That is the loop the current infostealer economy runs on, and shortening the gap between “your data is out” and “you know your data is out” is exactly what the feature is built for.
For a fuller breakdown of how the service compares on speeds, privacy fundamentals, and audited no-logs architecture, our NordVPN review walks through the details. NordVPN also holds a consistent spot near the top of most best VPN guides for exactly this kind of layered defense scenario, where the VPN itself is the first line and the additional features cover what the tunnel alone cannot.
NordVPN Basic at $3.49 per Month
NordVPN’s Basic plan is currently available at $3.49/month, which works out to $94.23 billed once for 27 months of service (24 + 3 free). That is a 69% discount off the standard rate. Annual renewal continues at $139.08/year, cancelable from the account dashboard at any time.
The Basic plan covers the core VPN across up to 10 devices with applications for Windows, macOS, Linux, iOS, Android, browser extensions, and router installation for whole-household coverage. Threat Protection Pro and Dark Web Monitor, the two features that matter most for the specific infostealer chain described above, sit in the higher Advanced and Ultra tiers. If your reason for signing up after reading this is to close the phishing pipeline that feeds these token dumps, those are the plans that actually do the job.
30-Day Money-Back Guarantee
NordVPN backs every plan with a 30-day money-back guarantee. If the service doesn’t fit the way you use your devices, you can request a full refund within the first month. Refunds are processed through 24/7 chat support, and funds typically return within 5 to 10 business days depending on the payment method used.
That gives you a full month to install the apps across your setup, test the tracker and phishing filter against the actual traffic hitting your inbox, and see whether the coverage holds up before the refund window closes. A note on the subscription: the $3.49/month rate applies to the first 27 months. Auto-renewal kicks in at the standard annual rate after that. If you would rather cancel or renegotiate before renewal, set a reminder in your calendar 7 to 10 days before the renewal date.
