AI/TLDR

Anthropic · 2026-08-30 · major

Claude sessions stolen by infostealer malware — Anthropic signs users out

Anthropic emailed Claude users that infostealer malware on their own computers copied active Claude session cookies, letting attackers replay the session and burn through paid usage. Anthropic revoked sessions and refunded charges.

Claude chat interface, illustrating hijacked Claude login sessions
BleepingComputer

Infostealer malware on user machines copied live Claude session cookies, so attackers drained paid usage without ever entering a password.

Quick facts

Who is affectedClaude users with infostealer malware on their own computer
What was stolenActive Claude session cookies, not passwords
Windows malware familiesVidar, LummaC2, StealC, RedLine, Acreed
macOS malware familyAtomic Stealer (AMOS)
Anthropic's responseRevoked sessions, removed saved payment methods, refunded unauthorized charges
What users should doRun a full malware scan, then change the password with two-factor authentication on

What is it?

Anthropic emailed affected Claude users on 2026-08-30 to say that infostealer malware running on their own computers copied their active Claude login sessions. Attackers then used those sessions to consume the victims' paid usage. Anthropic is clear that Claude itself was not the way in, and that the malware came from elsewhere on the machine.

How does it work?

Infostealers such as Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer on macOS, sweep an infected machine for saved passwords, browser cookies and locally stored credentials. A session cookie is already authenticated, so replaying it skips the login screen — and with it two-factor authentication and single sign-on. Anthropic responded on the account side: revoking sessions, deleting saved payment methods, and refunding charges it judged unauthorized.

Why does it matter?

The account-side cleanup does not touch the infected computer, so the next login can be stolen the same way. Anyone whose Claude usage drained on its own should scan for malware before logging back in, then change the password with two-factor authentication enabled and revoke other sessions. The wider point for developers is that an AI subscription is now a credential worth stealing, and a session cookie is the softest part of it.

Who is it for?

Claude subscribers and security teams that manage AI tool access

Frequently asked questions

How do I know if my Claude account was used by someone else?
Anthropic's notice points to one symptom: "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause." Because the attacker replays a stolen session rather than logging in, there is no failed-login trail — unexplained usage and unexpected charges are the signal.
Does two-factor authentication stop this attack?
No. The malware takes an already-authenticated session cookie instead of a password, so replaying that cookie skips the login step entirely. BleepingComputer and Security Affairs both report that this bypasses two-factor authentication and single sign-on, which is why Anthropic revoked the sessions itself rather than relying on users to re-secure their logins.
Was Claude or Anthropic breached?
No. Anthropic states: "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude." The infostealer families involved — Vidar, LummaC2, StealC, RedLine, Acreed on Windows and Atomic Stealer on macOS — harvest saved passwords and browser cookies from any infected machine.
Is signing out enough to fix it?
Signing out is not enough on its own. Anthropic warned that "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware. If it's still on your computer, your next login session could be stolen the same way." The advice is to run a full malware scan first, then change credentials and revoke other sessions.

Sources · 3 outlets

Tags

  • anthropic
  • claude
  • security
  • infostealer
  • session-hijacking
  • malware
  • account-takeover
  • session-cookies
  • vidar
  • lummac2
  • atomic-stealer

← All releases · Learn AI