Employee logging into an AI chatbot account on a work laptop, illustrating session hijacking risk

Your Employees' AI Accounts Are Becoming a Backdoor Into Your Business

A few weeks ago, we wrote about the risk of employees using ChatGPT and Claude at work without IT's knowledge. This month, that risk got sharper: security researchers confirmed that criminals are now actively hijacking Claude accounts not by cracking passwords, but by stealing the browser session itself. And the way back in doesn't stop at the AI chatbot. In some cases, it reaches straight into corporate Gmail and Google Drive.

How the attack actually works

Infostealer malware like Vidar, LummaC2, StealC, and RedLine has been around for years, quietly harvesting saved passwords and browser data from infected computers. What's changed is the target. Attackers now specifically harvest session cookies, the small file that proves you're already logged in, and replay them directly into services likeClaude. Because the cookie proves an active, already-authenticated session, the attacker never touches a login page. That means no password prompt, and no multi-factor authentication challenge to get past. MFA doesn't help if the thief never has to log in at all.

Once inside, criminals aren't just snooping. They burn through the account's paid usage credits, trigger unauthorized charges if auto-reload is enabled, and, perhaps more concerning for a business, use the stolen AI capacity to write phishing emails, build malicious infrastructure, and analyze other stolen data. Your employee's Claude subscription becomes the attacker's tool.

The part that should worry IT teams most

Here's where it gets serious for businesses specifically. Many employees connect their personal AI accounts to work tools, granting an AI assistant access to their Gmail inbox or a Google Drive folder to help draft emails or summarize documents. That authorization persists as an OAuth grant, separate from the AI account's login session.

When Anthropic signs a compromised user out of Claude to stop the stolen session, that action invalidates the session, but it does not revoke the underlying Google or Microsoft authorization Claude was already granted. And because the AI subscription is a personal, self-serve, card-billed account sitting entirely outside thecompany's identity systems, corporate IT admins often don't even know the grant exists, let alone have a way to revoke it through their own admin console. A single infected personal laptop can leave a persistent opening into corporate email that no amount of company-side password resets or SSO enforcement can close on its own.

This isn't a rare event

Security researchers tracking infostealer activity found that more than 1 in 10 infostealer infections in 2025 exposed enterprise credentials, and that rate is projected to reach 1 in 5 by the second half of 2026. Over 1.17 million info stealer logs analyzed last year contained both stolen enterprise credentials and session cookies together- the exact combination that lets an attacker skip past MFA entirely. This isn't a hypothetical edge case; it's a fast-growing and increasingly precise category of attack.

What businesses should do about it?

•      Move employees off personal AI accounts for work. Business-tier ChatGPT, Claude, and Copilot accounts can be tied to your company's SSO and identity provider, which means IT can actually see and revoke sessions and connected app grants when something goes wrong.

•      Audit connected app permissions regularly. Check what's authorized against your Google Workspace or Microsoft 365 tenant, including personal accounts employees may have connected, and revoke anything unrecognized or unnecessary.

•      Keep real-time anti-malware running on every endpoint. Infostealers typically arrive through cracked software, fake installers, and malicious ads the same well-known delivery methods that up-to-date endpoint protection is built to catch before they execute.

•      Treat session hijacking as an MFA blind spot. MFA is still essential, but it doesn't stop a stolen,already-authenticated session. Session monitoring and short session lifetimes matter too.

•      Train employees on whatto do if something feels off: unexpected charges, unfamiliar activity, or asecurity alert from an AI provider should trigger an immediate device scan, nota shrug.

How Cynergy Information Technology can help

This is precisely the kind of gap that falls between “the employee's problem” and “IT's problem” and attackers are counting on that confusion. Cynergy Information Technology can help you move your team onto properly governed, business-tier AI accounts, audit what's already connected to your Google or Microsoft environment, and make sure every endpoint has real-time protection against infostealers before they ever get the chance to steal a session. Reach out to Cynergy IT to get a clear picture of where your business stands.