Why a Stolen AI Session Should Concern Your Business
Two-factor authentication is one of the most important protections for your business accounts. However, a recent security incident involving stolen Claude session cookies shows why 2FA alone cannot protect every stage of an online session.
For a Malaysian SME, the issue is practical. You or your employees may use AI tools to summarise customer emails, review documents, prepare proposals, analyse spreadsheets or connect to Google Workspace. If an employee’s computer is infected, an attacker may steal the browser session that was created after login. The attacker can then reuse that session without entering the password or passing the 2FA prompt again.
This is not only an AI subscription problem. If the AI account has permission to access Gmail, Google Drive or other work systems, a stolen session may become a route into business information. The incident reported by VentureBeat is a reminder that your business must manage connected applications, personal accounts and employee devices together—not as separate security concerns.
What Happened
Anthropic warned affected Claude users that infostealer malware had stolen Claude login sessions from infected computers. The malware families named in the notification included Vidar, LummaC2, StealC, RedLine and Acreed on Windows, as well as Atomic Stealer on some Mac computers. The report said the malware can copy browser login cookies and saved passwords. Source: VentureBeat
A session cookie is created after you successfully log in. It tells a website that your browser has already passed authentication. If criminals copy that cookie and replay it from another device, the service may treat them as an already authenticated user. The attacker does not necessarily need to revisit the login page, enter the password or trigger 2FA again. The report describes this as session-cookie replay bypassing the login checkpoint rather than breaking the 2FA system itself. Source: VentureBeat
Anthropic signed affected accounts out, removed saved payment methods and refunded identified unauthorised usage, according to the report. Those actions may limit direct account misuse, but they do not automatically answer a more serious question: what could the stolen session access while it was active?
Claude connectors can retrieve information and take actions inside connected services according to the user’s permissions. The report stated that read and search operations can run without approval, while actions such as sending, replying, forwarding, sharing, moving and deleting are approval-gated by default. Source: VentureBeat
Why This Matters for Malaysian SMEs
Many Malaysian SMEs operate with a lean technology setup. A founder may be the Google Workspace administrator, finance approver and person responsible for customer data. Employees may use personal subscriptions or sign up for software independently because the business needs a fast solution. This flexibility helps work move quickly, but it can create accounts and access grants that nobody in the business can see clearly.
Imagine an employee connects a personal AI account to a work Gmail inbox to help draft replies. The Google account may have approved that connection once. If the AI account later has a stolen session, the attacker could potentially reach the information available through that connection. Your Google administrator may not know that the grant exists, while the AI service may not have an administrator who can control the personal account. The report specifically highlighted this gap between personal, self-service AI accounts and corporate identity management. Source: VentureBeat
The exposure can be significant even when the attacker is not trying to send emails. Customer quotations, employee records, supplier contracts, identification documents, banking correspondence and internal discussions can all be sensitive. An attacker may also use stolen information to impersonate your staff, prepare convincing payment scams or identify which customers and suppliers are most valuable.
The source article cited LayerX research reporting that 47% of enterprise AI conversations used personal identities, with Claude at 61%. Treat this as an industry warning rather than a measurement of your own company: if staff use AI under personal accounts, your business may have limited visibility and limited ability to revoke access. Source: VentureBeat
Key Checks for Your Business
| Risk area | What you should check | Practical action |
|---|---|---|
| AI accounts | Which employees use AI tools and under whose identity? | Keep a simple register of approved AI applications and account owners. |
| Connected services | Can an AI tool read Gmail, Drive, calendars or customer systems? | Review connected applications and remove grants that are no longer needed. |
| Browser sessions | Are staff signed into work systems on unmanaged computers? | Require business work to use managed devices where possible. |
| Downloads | Do employees install software from search ads, unofficial websites or pirated sources? | Allow downloads only from verified vendor pages and block unknown installers. |
| Incident response | Can you quickly sign out accounts and revoke connected access? | Document the steps and test them with your administrator. |
What You Can Do This Week
Start by listing every AI service used for business work. Include tools used for writing, design, coding, customer support, transcription, recruitment and document analysis. Record whether each account is personal, shared or controlled by the company. A tool that is not on your list may still be accessing business information through a staff member’s browser.
Next, inspect connected applications in your Google Workspace or Microsoft environment. Remove old AI tools, browser extensions and integrations that are no longer required. Ask employees to report any application that requests access to Gmail, Drive, contacts or calendars. Do not assume that an application is safe simply because it uses an established AI brand.
Improve device hygiene as well. Infostealers are commonly delivered through unsafe downloads, fake installers, malicious browser extensions, phishing messages and unauthorised software. The source article described a fake Claude download campaign that used a spoofed page and a sponsored Bing advertisement, while another campaign used a fake installer website. Source: VentureBeat
Tell your team to access AI applications through a saved official bookmark rather than a search advertisement. Keep operating systems, browsers and security software updated. Block local administrator rights for ordinary users where practical. If a staff member installed pirated software or entered credentials into a suspicious site, treat the device as potentially compromised and begin an account review immediately.
2FA protects the login event. It does not guarantee that every active browser session, connected application or previously approved access grant is safe.
The Bigger Picture
AI security is moving beyond the question of whether an employee has a strong password. The more important questions are what the AI tool can read, which identity authorised it, how long that access remains active and who can revoke it. An AI assistant with broad permissions can become a useful employee—or a concentrated access point into several business systems.
The source article also discussed safer agent integration patterns, including governed identities, separate read and write scopes and write actions disabled by default. These principles are useful even if your business is small. Give AI tools the narrowest access they need. Prefer read-only permissions for summarising or searching. Require a human approval before sending messages, changing records or sharing files. Avoid long-lived, broadly scoped API keys stored on employee devices or in shared systems. Source: VentureBeat
You do not need a large security department to apply these controls. Assign one person to maintain the AI application list, review connected services monthly and handle suspected device infections. Include AI access in staff onboarding and offboarding. When someone leaves, remove their accounts, revoke their sessions and review any applications they connected to company data.
For Malaysian SMEs, the goal is not to stop useful AI adoption. It is to make sure convenience does not quietly create an unowned path into your business. Treat every AI connector as a business permission, every browser session as a security asset and every unmanaged download as a possible entry point. That approach lets you use AI productively while keeping control of the information your customers and team trust you to protect.
Ready to Streamline Your Operations?
Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →