AI is quickly becoming part of everyday business life. Whether it’s helping write content, analyse information, support customers or speed up everyday tasks, more businesses are finding ways to make AI work for them.
But, as with any technology that becomes widely used, cyber criminals are paying attention too.
Recent research from Okta has highlighted a cyber security risk involving stolen session tokens and AI accounts. It sounds quite technical, but the idea behind it is actually fairly simple – and it’s something businesses should be aware of.
So, what is a session token?
Think about what happens when you log into an online account.
You enter your password, complete your Multi-Factor Authentication (MFA) check and you're in. You can then move around the platform without having to prove who you are every few minutes.
A session token is part of what makes that possible. It essentially tells the system, this person has already logged in and been verified.
Normally, that makes life easier. The problem starts if that token falls into the wrong hands.
If a cyber criminal manages to steal a valid session token, they may be able to use it to access the account as though they were the person who originally logged in.
In other words, instead of trying to guess your password or get through your MFA, they're potentially stealing proof that you've already passed those checks.
How are these tokens being stolen?
One of the threats businesses need to be aware of is infostealer malware.
As the name suggests, this type of malware is designed to steal information from an infected device. That could include saved passwords, browser cookies, API keys and session tokens.
Once that information has been stolen, criminals can look for anything useful that could give them access to online accounts and services.
And that's where AI comes into the picture.
Why are cyber criminals interested in AI accounts?
Think about how much more we're starting to trust AI with.
Businesses are using AI for research, marketing, customer service, coding, analysing information and plenty more. In some cases, AI tools are also being connected to other business platforms and company data.
That makes these accounts much more interesting to cyber criminals than they might have been a few years ago.
The more information and access an account has, the more valuable it could potentially become if someone manages to get inside.
This doesn't mean businesses should be frightened of using AI. Far from it. But AI accounts need to be treated with the same care as any other important business system.
What about MFA?
MFA is still one of the most important security measures a business can have in place, and we would absolutely recommend continuing to use it.
What this research highlights is that MFA shouldn't be where your cyber security ends.
If someone steals information from a session that has already been authenticated, the situation is slightly different from somebody simply trying to guess a password.
That's why businesses need several layers of protection rather than relying on one security measure alone.
What does this mean for UK organisations?
For UK organisations, the concern isn't simply someone gaining access to an AI account. It's what that account could potentially give them access to.
If employees are using AI tools to work with company information, customer data, internal documents or connected business systems, a compromised account could potentially expose information that the organisation has a responsibility to protect.
It also highlights the importance of knowing which AI platforms are being used across the business. As AI becomes part of everyday working life, organisations need to make sure it's included within their wider cyber security policies, access controls and data protection procedures.
Ultimately, AI shouldn't be treated as something separate from the rest of your IT environment. If it's being used to handle business information or connect with other systems, it needs to be considered as part of your overall cyber security strategy.
What should businesses be doing?
There doesn't need to be a dramatic response to developments like this. It's more about making sure your cyber security keeps up with the technology your business is using.
A few sensible things to consider include:
- Keep devices, browsers and software up to date.
- Use good endpoint protection and monitoring.
- Continue using MFA wherever possible.
- Know which AI tools employees are using.
- Think carefully about what company information is being shared with AI platforms.
- Limit account permissions where possible.
- Remove old or unnecessary login sessions.
- Train employees to recognise phishing attempts, suspicious downloads and other common threats.
- Include AI within your existing cyber security policies and reviews.
One of the biggest things is simply having visibility. Do you know which AI tools are being used across your business, what information they're being given and how those accounts are protected?
If the answer is no, that's probably a good place to start.
Keeping up with a changing cyber security landscape
Cyber security is constantly changing. AI is just the latest development creating both new opportunities for businesses and new opportunities for criminals.
That doesn't mean businesses need to panic every time a new cyber threat makes the headlines.
It does mean they need to keep adapting.
At AdaptiveComms, we believe good cyber security should be practical. It's about understanding the risks that are relevant to your business, putting the right protection in place and making sure that protection continues to evolve as your technology does.
📞 0808 281 0808
If you'd like to understand where there could be gaps in your current cyber security setup, get in touch with the AdaptiveComms team. We can help you review your existing protection and make sure your business is prepared for the threats that matter.




.avif)





