Case Study · Shadow AI
101,000 stolen ChatGPT logins showed how much shadow AI use is actually happening
What happened
Cybersecurity firm Group-IB identified more than 101,000 devices with saved ChatGPT login credentials compromised by info-stealing malware and traded on dark-web markets, with victims across France, Spain, Germany, Italy, and Poland. The credentials were harvested from personal devices, not corporate security infrastructure - but the accounts had company data sitting in their chat histories.
The scale is the real finding: unsanctioned AI use inside companies is large and largely invisible to leadership until something like a malware campaign surfaces it. None of the affected companies had a way of knowing this was happening until an outside security firm went looking.
The business problem
Employees were using personal AI accounts for work without any company visibility into it, and that invisible usage became a real security exposure the moment a common piece of malware found it.
What could have helped
- Shadow AI use is normal, not rare - the question is whether leadership finds out from an audit or from a breach
- A shadow-AI usage audit is one of the fastest, lowest-cost ways to see where the actual exposure is
- Personal-device AI use routes company data outside any security perimeter the company controls
- The fix isn't just a ban - it's giving people an approved, secure alternative before they go find their own