Telegram-posted 7 GB infostealer dump exposing AI tokens and PII
Data Leak
Summary
Hide ▲
Show ▼
The 7 GB infostealer dump posted on Telegram exposed replayable authentication tokens, JWTs, JWEs, API keys, and plaintext PII, creating immediate account-takeover risk for AI and cloud services. The leak contained data from 5,871 infected machines across 162 countries and included token material tied to Google, Microsoft, Anthropic, and OpenAI. Because many of the secrets were still valid, attackers could replay them to bypass passwords and MFA.
Related Happenings
23AndMe hit by network compromise
Incident
H score55
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
About this happening:
23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
23AndMe hit by network compromise
IncidentAbout this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
Latest development: 17.07.2026 17:30
23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.
Tchap public chat data leak
Data Leak
H score52
First: 12.06.2026 10:09
Last: 12.06.2026 10:09
Sources 1
About this happening:
The Tchap data leak exposed public-sector user information for 73,467 agents after a compromised user account was used to access non-encrypted public chat rooms. The e...
Tchap public chat data leak
Data LeakAbout this happening: The Tchap data leak exposed public-sector user information for 73,467 agents after a compromised user account was used to access non-encrypted public chat rooms. The e...
Unnamed organization stolen data published on DLS
Data Leak
H score35
First: 06.05.2026 16:00
Last: 06.05.2026 16:00
Sources 1
About this happening:
Stolen data from an unnamed organization was later posted on a data leak site (DLS), confirming exposure and increasing extortion pressure. The publication followed an...
Unnamed organization stolen data published on DLS
Data LeakAbout this happening: Stolen data from an unnamed organization was later posted on a data leak site (DLS), confirming exposure and increasing extortion pressure. The publication followed an...
Moltbook wide-open database exposure
Data Leak
H score52
First: 22.04.2026 13:41
Last: 22.04.2026 13:41
Sources 1
About this happening:
The Moltbook database exposure placed 35,000 email addresses and 1.5 million agent API tokens at risk, creating immediate potential for account hijacking and credentia...
Moltbook wide-open database exposure
Data LeakAbout this happening: The Moltbook database exposure placed 35,000 email addresses and 1.5 million agent API tokens at risk, creating immediate potential for account hijacking and credentia...
Moltbook Supabase database exposure
Data Leak
H score45
First: 08.02.2026 09:32
Last: 08.02.2026 09:32
Sources 1
About this happening:
A misconfigured Supabase database exposed Moltbook data, putting API authentication tokens, email addresses, and private messages at risk of unauthorized acces...
Moltbook Supabase database exposure
Data LeakAbout this happening: A misconfigured Supabase database exposed Moltbook data, putting API authentication tokens, email addresses, and private messages at risk of unauthorized acces...
Timeline
-
09.09.2026 17:23 1 articles · 2h ago
Telegram channel releases 7 GB infostealer dump with AI tokens
Initial DisclosureA Telegram channel released a 7 GB infostealer dump that exposed data from 5,871 infected machines across 162 countries, including unexpired authentication tokens, JSON web tokens, JSON Web Encryption data structures, and API keys tied to AI and cloud services such as Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, Pika AI, OpenAI, Groq, and OpenRouter.
Show sources
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA — thehackernews.com — 09.09.2026 17:23
-
09.09.2026 17:23 2 articles · 2h ago
Okta analyzes 7 GB infostealer dump and finds replayable AI tokens
Technical Analysis UpdateOkta's analysis of the 7 GB infostealer dump identified 1,843 unexpired JWTs and JWEs on the release day, 2,937 authentication-related JWE structures, 555 JWTs likely tied to AI services, and 24 still-valid API keys for services including Google Gemini, OpenAI, Groq, and OpenRouter. The same dataset also contained plaintext personally identifiable information in 17.7% of the 44,791 JWTs, creating account-takeover and social-engineering risk for Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
Show sources
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA — thehackernews.com — 09.09.2026 17:23
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA — thehackernews.com — 09.09.2026 17:23