
Small businesses are becoming more comfortable using artificial intelligence tools for research, writing, customer communication, coding, and document review. That convenience also creates another account that must be protected.
Recent reports say attackers used information-stealing malware, commonly called an “infostealer,” to copy active Claude login sessions from infected computers. The attackers could then access affected accounts and consume their paid usage.
The important distinction is that the reported activity did not result from malware installed through Claude or a reported breach of Claude itself. According to notifications described in the reporting, the malware was already present on users’ computers.
When an employee signs in to an online service, the browser usually keeps that person signed in for a period of time. It does this using a small piece of session information that tells the service the user has already completed the login process.
Think of it like the temporary wristband given to someone after admission has been checked. The person does not have to present a ticket every time they move to another area.
If malware steals that active session, an attacker may be able to reuse it without entering the password again. In some circumstances, this can also bypass the usual multifactor authentication prompt because the original session has already been approved.
This does not make multifactor authentication unimportant. MFA still stops many account attacks. It means businesses must also protect the computer and browser where an authenticated session is stored.
Information-stealing malware is designed to collect valuable information from a device. Depending on the malware and the applications in use, that information could include:
An employee who uses the same browser for AI tools, Microsoft 365, banking, payroll, customer systems, and vendor portals may have several valuable sessions open at once.
Unauthorized AI account use can also create billing problems or expose prompts and previous conversations. The potential business impact becomes more serious when employees place customer information, contracts, internal procedures, or proprietary material into an AI service.
Ask employees to report unusual account activity promptly, including:
One unusual account may be the first visible sign of a wider device infection.
Claude provides an Active Sessions section under its account settings. Users can review browsers, devices, approximate locations, and recent activity, then terminate sessions they do not recognize.
Businesses should perform similar reviews for important email, cloud, finance, and administrative accounts when those services provide the option.
Employees should use managed business computers for sensitive work whenever possible. Those devices should receive operating-system, browser, security, and application updates consistently.
Personal computers with unreviewed software, browser extensions, or unofficial downloads can introduce risk into business accounts.
Infostealers are often distributed through malicious applications and unofficial downloads. Employees should obtain software only through approved sources and should not install cracked programs, random utilities, unofficial AI clients, or “free” tools without review.
Business devices need centrally managed security protection that can identify suspicious downloads, programs, and account activity. Monitoring should cover Windows and macOS devices used to reach company information.
Define which AI services are approved, which accounts employees should use, and what information may be entered. Sensitive customer, financial, health, legal, or employee information should not be placed into an AI service without an appropriate business review.
Do not treat the problem as a password-only incident.
Disconnect the affected computer from the business network and contact the company’s legitimate IT provider. From a known-clean device, terminate suspicious sessions and follow the provider’s instructions for resetting affected credentials.
The computer should be professionally checked for malware before the employee signs back into business services. Otherwise, a new session or password could be stolen again.
The IT team should also review other accounts accessed from the device, relevant security logs, connected applications, browser extensions, and recent downloads. Avoid relying on a quick browser cleanup when the underlying computer may remain infected.
AI accounts are becoming part of normal business operations. They deserve the same managed security, access reviews, usage policies, and incident procedures as email and cloud-storage accounts.

Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day

Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety

I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!

I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.

Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.

It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.

Himala and his team from Cybernetic Networks, Inc. has been an integral part of our successful retail business for the past 20 years. He is extraordinarily knowledgable and always available for our IT needs. Thanks to Himala and his team we are always up and running.