Anthropic Warns Infostealer Malware Is Stealing Claude Sessions, Risking Unauthorized Account Access

Views: 93 views

477/69 Tuesday, September 1, 2026

Anthropic has warned Claude users after finding cases where infostealer malware on users’ computers stole login sessions and used those sessions to access Claude accounts and consume account usage quotas without authorization. The incident was not caused by malware directly related to Claude or installed through the Claude service. Instead, it originated from users’ computers that may have been infected with malware designed to steal local data, such as passwords stored in browsers, login cookies, and credentials from other applications.

Reports indicate that infostealers can copy already authenticated login sessions, allowing attackers who obtain those sessions to access accounts without re-entering passwords or completing two-factor authentication (2FA) again. Anthropic stated that several malware families were involved, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer, or AMOS, affecting some Mac users. This type of malware often infects devices through untrusted downloads or malicious applications before collecting data from the system and sending it to attackers for further use.

Anthropic revoked the stolen sessions from affected users’ accounts, removed saved payment methods, and refunded additional service charges found to have resulted from this activity. However, revoking sessions does not remove malware from the device. If the malware remains present, new sessions may be stolen again. Affected users should scan for and remove malware, change passwords from a secure device, revoke unknown sessions, and review other accounts that may use the same credentials to reduce the risk of repeated unauthorized access.

Source: https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/