An infostealer crew no longer needs your password. It wants in to your AI session. Recent reporting describes criminals stealing session tokens from AI assistant users, including users of Anthropic's services. The reason is simple: a live agent session carries your identity, your context, and your authority in one object.
Steal the session, and you inherit the documents the agent can read, the systems it can reach, the skills it possesses, and the voice it uses when it writes on your behalf. That makes the agent an insider in every sense that matters to a security team.
Compare that with a stolen password. A password gets an attacker to a login page, where MFA, device checks, and risk scoring still stand in the way. A session token has already passed all of those tests. For the attacker, it is the difference between a forged concert ticket that still has to get through the gate and an access wristband already on your wrist.
Tomorrow at AI & NHI Impact Day in Munich, this is the argument we will put on the table. Here is a first look at it:
Every insider control assumed a human
Organizations spent two decades building insider threat programs. I helped define that security category, and I know what went into it: least privilege, user and entity behavior analytics (UEBA), session monitoring, and segregation of duties. Every one of those controls assumed a human behind the keyboard.
UEBA builds a baseline of how a person works: the hours they keep, the systems they touch, the volume of data they move. Segregation of duties splits sensitive tasks across human roles, so that no single person can both request and approve a payment. Session monitoring watches what a person does for signs of harmful intent.
AI agents break each of these assumptions. An agent acts with our authority, so its access is our access. It works at machine speed, so its volume would trip any human-centric detection. The agent often holds the permissions of several roles at once, because it was set up to help across a whole workflow, thus potentially violating segregation of duties. And it sits inside our trust boundary, where most monitoring is weakest.
In 2026, many organizations are deploying agents with broad permissions, deep context access, and the ability to act, without the controls they would demand for a new employee with the same reach. The threat model we perfected for humans is missing for the non-human colleagues we just gave the keys to.
The gap is not a lack of awareness. Most security leaders know that agents hold broad access. The gap is ownership: identity teams see agents as applications, application teams see them as productivity tools, and the insider threat program does not see them at all.
Four attack paths, one pattern
Evidence from recent weeks shows attackers already treating the agent as the trusted path into the enterprise. Four vectors stand out.
- Session theft. Infostealers now harvest AI session tokens alongside browser cookies. A stolen agent session skips the login, the MFA prompt, and the device check, because the session has already passed them.
- Prompt injection at scale. Research has moved from one-off demonstrations to industrialized evaluation. Work such as CAITLYN, LongPIBench, and ECLIPSE shows how big the problem is. LongPIBench finds that simple injections hidden in long documents bypass state-of-the-art defenses. ECLIPSE builds stealthy attacks that steer long-horizon agents through multi-step tool chains. CAITLYN finds that static defenses stay vulnerable to new injection techniques. One poisoned document, email, or web page can redirect an agent long after it was initially reviewed and deployed.
- Consent-based social engineering. The ClickFix campaign compromised 31 organizations through fake consent screens. People approved what they saw, and machines then executed what they approved. Agents widen that gap: a user grants a permission once, and the agent uses it from that point forward.
- Poisoned supply chains. The TanStack npm poisoning and the TeamPCP arrests show malicious components flowing into the same package pipelines that coding agents pull from. An agent that installs dependencies on its own can import an attacker's code with the developer's full privileges, but without their consent.
The pattern is the same in each case. The attacker does not break the trust boundary; the attacker borrows an agent that already sits inside it. Traditional controls look for an outsider trying to get in, or a person behaving oddly. They are not built to question an authorized agent doing what it appears to have been asked to do, at speeds far beyond any human.
This is why the insider threat frame fits for AI agents. An insider is dangerous because the organization has already decided to trust them. The same is true of an agent, and the attacker's job is simply to leverage that trust. Like human insiders, agents do not need an attacker to cause harm. A poorly scoped or misconfigured agent can delete records, leak data, or pay the wrong supplier while it tries to do its job.
What comes next
If the controls we built for human insiders miss agents, what does that do to fraud detection, and what should security teams do about it? We will take both questions up after the event, with what we hear in Munich.
Until then, one thing you can start today: find out how many agents your organization runs, who owns them, and what they can reach. You cannot apply least privilege to an identity you do not know exists.
Join us at AI & NHI Impact Day, October 6 in Munich to continue the conversation. Register here.