By David Johnson, The Fulcrum Group

Artificial intelligence is changing how businesses operate. Employees use AI to draft emails, summarize meetings, analyze data, and speed up everyday work.

But as AI adoption grows, so does a new cybersecurity risk many small business leaders have not considered: what happens when attackers steal access to your AI accounts?

Anthropic recently warned some Claude users that infostealer malware had compromised their computers, allowing attackers to hijack active login sessions and use their Claude accounts without authorization. In response, Anthropic signed affected users out, removed stored payment information, and refunded unauthorized charges it identified.

The story involves Claude, but the lesson applies to every organization using AI tools — Microsoft Copilot, ChatGPT, Gemini, and the rest.

The Real Problem Isn’t AI

The malware Anthropic identified was not targeting Claude directly.

According to the company, the infections came from common infostealer malware families designed to harvest passwords, browser cookies, and application credentials from infected devices. Anthropic said the malware typically arrives through unofficial downloads or malicious applications.

In other words: this was not an AI failure. It was a cybersecurity failure.

The AI platform simply became another business application attackers could reach after compromising a user’s computer. It just as easily could have been Copilot, or Microsoft 365 itself.

Why Small and Mid-Sized Businesses Should Pay Attention

Many organizations are adopting AI quickly without considering how it fits into their security strategy. Employees may be using AI tools that touch:

  • Customer information
  • Internal business discussions
  • Financial data
  • Proposals and contracts
  • Strategic planning documents
  • HR and operational information

If an attacker gains access to an employee’s device and steals active browser sessions, they may gain far more than an email account. They can potentially inherit access to every cloud application that employee is currently signed in to.

The more integrated AI becomes with everyday work, the more valuable those accounts become to cybercriminals. That is as true for a 30-person firm in Fort Worth as it is for an enterprise in Dallas.

The Rise of Session Theft

One of the most important takeaways from this incident is that attackers did not necessarily need to know the user’s password.

Anthropic indicated that the malware harvested browser login cookies and session data, which allowed attackers to access affected accounts.

For business leaders, that means traditional advice like “use a strong password” is no longer enough. Modern cybersecurity has to include:

  • Endpoint protection
  • Browser security
  • Multi-factor authentication
  • 24×7 cybersecurity monitoring with managed detection and response
  • Identity monitoring
  • Threat detection and response
  • User awareness training

Assume credentials will eventually be targeted, and build layered defenses accordingly.

What This Means for Microsoft 365 Copilot Users

As Microsoft 365 Copilot adoption grows, organizations should recognize that Copilot inherits the permissions of the user.

If a compromised account has access to company email, files, Teams conversations, SharePoint data, and OneDrive content, the business impact extends well beyond a single application.

That reinforces an important principle: AI security starts with identity security. Protecting Microsoft 365, Entra ID, endpoints, and user accounts is foundational to protecting AI access.

Three Questions Every Business Leader Should Ask

1. How are we protecting employee devices?

If malware infects a workstation, what controls are in place to detect and stop it? Do you have SOC-backed managed detection and response watching for threats like infostealer malware around the clock?

2. Do we have visibility into compromised accounts?

Could your IT team quickly identify suspicious sign-ins, unusual activity, or credential theft? Managed detection and response connected to Microsoft 365 can identify compromised accounts and disable them before an attacker steals data.

3. Are we treating AI as a business application?

Most organizations have governance and security policies for email, file sharing, and financial systems. Do those same policies now apply to AI?

The Bigger Lesson

The most interesting part of this story is not that Claude users were targeted. It is that cybercriminals are beginning to recognize the value of AI accounts.

As AI becomes more deeply embedded in business operations, attackers will keep looking for ways to exploit access to those systems. The organizations that benefit most from AI will not simply be the ones that adopt it first. They will be the ones that adopt it securely.

The future of AI in business is not just about productivity. It is about productivity, governance, and cybersecurity working together.

Leadership Takeaway

Before asking “How can AI make my team more productive?”, ask “How are we protecting the systems, identities, and devices that provide access to AI?” The answer to the second question may determine the success of the first.

Book a free cybersecurity or AI discovery call with the Fulcrum Group team and we will walk through the three questions above with you.