Threat Brief — 2026-09-09 — AI Identity Hijack & MFA Recovery Gaps
Two emerging attack patterns target the enterprise identity layer: "workflow identity hijacking" that bypasses standard controls through unauthenticated entry points, and exploitation of MFA account-recovery processes as the weakest link in otherwise protected accounts. Separately, infostealer logs are being weaponized to extract replayable AI-service tokens that bypass MFA for major model providers, and a single exposed API endpoint leaked 220,000 private photos and medical records. US intelligence agencies attribute industrial-scale AI model distillation to six Chinese firms extracting billions of tokens from American frontier models since late 2024.
Top items
- US attributes industrial-scale AI distillation to six Chinese firms. US cybersecurity and intelligence agencies report that six China-based AI companies have conducted systematic distillation attacks against American frontier AI models since at least late 2024, extracting billions of tokens. This represents state-enabled intellectual-property exfiltration at scale targeting the AI sector specifically. First reported 2026-09-08 by CISA. (src: BleepingComputer)
- Single API endpoint leaks 220,000 private photos and medical records. One exposed API endpoint was responsible for leaking a large volume of sensitive medical data and private photographs, underscoring how a single misconfigured interface can cause mass data exposure without any sophisticated exploit. First reported 2026-09-09. (src: Anquanke)
- Infostealer logs expose replayable AI tokens that bypass MFA. Cybercriminals are harvesting authentication tokens from infostealer logs to create "stolen keys" that grant persistent access to AI tools from providers including Google and Anthropic. These tokens are replayable and bypass MFA, meaning standard account protections do not mitigate the theft. First reported 2026-09-09. (src: The Hacker News)
- "Workflow identity hijacking" bypasses enterprise security via unauthenticated entry points. A newly described attack class exploits identity-based AI workflows by sending requests through unauthenticated entry points, allowing attackers to hijack organisational data while bypassing standard security controls. The technique targets the intersection of AI integration and identity management. (src: Dark Reading)
- Veradigm discloses patient data breach after ransomware gang claims attack. Healthcare technology company Veradigm confirmed a data breach after a cybersecurity incident at a third-party vendor exposed patient personal data. The Gentlemen ransomware gang has claimed responsibility. First reported 2026-09-09. (src: BleepingComputer)
- MFA account recovery identified as the primary attack path for account takeover. Attackers are increasingly shifting focus from MFA-protected login flows to the account-recovery processes used to reset passwords and authentication methods. Service-desk identity verification is cited as the critical weak point, as recovery workflows often lack the same strong authentication requirements enforced at login. (src: BleepingComputer)
Themes
Identity is the new perimeter — and it's fracturing. Three of today's items converge on the same theme: attackers are routing around strong authentication by targeting adjacent identity surfaces. Infostealer tokens bypass MFA by replaying session credentials; workflow identity hijacking exploits unauthenticated AI integration points; and account-recovery processes are being targeted as the fallback when direct login is too hard. Organisations that have invested heavily in MFA at the front door may still be exposed through side doors that were never hardened to the same standard.
AI services are now both target and attack vector. The China-attributed distillation campaign, replayable AI token theft, and workflow identity hijacking all illustrate that AI platforms are simultaneously high-value targets (for model IP and user data) and novel attack surfaces (via integration points and agent workflows). Securing AI access requires treating API tokens and agent identities with the same rigour as human credentials.
