Cybersecurity

Anthropic Warns of Information-Stealing Malware Hijacking Claude Sessions

Anthropic warned that information-stealing malware was being used to steal active login sessions to Claude, allowing attackers to consume usage quotas and access accounts without going through the password and two-factor authentication again. The company says it is signing affected accounts out, removing saved payment methods, and refunding unauthorized charges, but emphasizes that these measures do not remove the malware from the user’s device.

2026-08-30
3 min read
12 views
فريق تحرير certi.news
Anthropic Warns of Information-Stealing Malware Hijacking Claude Sessions

Anthropic warned some Claude users that information-stealing malware installed on computers had stolen active login sessions, which were then used to access accounts and consume usage quotas without the owners’ knowledge. The company sent an alert to affected users, explaining that it is signing compromised accounts out, removing saved payment methods, and refunding charges it identifies as unauthorized.

Anthropic said its investigation is ongoing, but linked the cases to general-purpose information-stealing malware that typically infects devices through malicious downloads or applications. The malware identified by the company includes Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer, known as AMOS, on a limited number of Mac devices.

How Were the Stolen Sessions Used?

Information stealers can copy data stored locally, such as browser passwords, login cookies, and credentials for other applications. Anthropic explained that a Claude session was likely among the data collected by the malware, after which an attacking party began extracting and using those sessions.

Because a stolen session is already authenticated, the attacker may not need to enter the password or pass two-factor authentication again. One indicator cited by the company is that usage limits appear to have renewed and then been consumed quickly at a time when the user was not using Claude.

What Is Anthropic Doing for Affected Users?

The company says that revoking compromised sessions stops the use of stolen sessions, while removing saved payment methods helps limit unauthorized purchases. However, it stressed that signing out does not remove the malware from the device; if the malware remains active, the next login session may be stolen in the same way.

Anthropic recommends that affected users change their credentials, revoke other sessions, and remove the malware from their computers before logging in again. In the case of a user who shared the company’s message on Reddit, the user said they had downloaded a pirated game, providing a possible explanation for the device’s infection.

Why Does This Matter?

These incidents show that account protection does not stop at passwords and two-factor authentication if the device itself is infected with malware that steals authenticated browser sessions. The actual change here is not the discovery of a vulnerability in Claude, as Anthropic confirmed that the malware was not associated with or installed through the service, but rather the use of stolen session data to drain account resources and potentially exploit saved payment methods.

Open questions remain about the scope of the incidents, the number of affected accounts, and how the sessions used were identified. Anthropic’s measures address access to the account, but they do not replace inspecting the infected device and removing the malware before creating a new session.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news