Anthropic Signs Out Users After Infostealers Hijack Claude

Anthropic said it is signing Claude users out of their accounts, stripping saved payment methods, and refunding unauthorized charges after discovering that infostealer malware on users' own computers was hijacking active login sessions to burn through paid usage.
According to the company, the malware itself has nothing to do with Claude. It is general-purpose infostealer software that typically arrives through malicious downloads or fake apps and harvests whatever is stored locally on an infected machine: browser passwords, login cookies and credentials for other services. Attackers then sift through that stolen data for active Claude session cookies and reuse them to access accounts as if they were the legitimate owner.
Because the sessions are already authenticated, the technique sidesteps passwords and two-factor authentication entirely. A session cookie keeps a browser marked as signed in after the login step, so an attacker who steals and replays it inherits that authenticated state without ever needing a password or a one-time code.
Anthropic said it has identified five infostealer families behind the campaign on Windows — Vidar, Lumma (LummaC2), StealC, RedLine and Acreed — along with Atomic Stealer (AMOS) on a small number of Macs. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company said, adding that signing affected users out stops the stolen sessions from being reused but does not remove the malware from an infected computer.
As part of its response, Anthropic is revoking compromised sessions, removing saved payment methods from affected accounts, and issuing refunds for charges it identifies as unauthorized. Security researchers tracking the campaign note that infostealer-driven session hijacking has become a increasingly common way for attackers to quietly consume paid subscriptions across AI services, since stolen cookies are harder for users to notice than a stolen password.
Disclosure: NewUJ's editorial process uses Anthropic's Claude models.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.