READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Anthropic Warns Infostealer Malware Is Hijacking Claude Accounts by Stealing Login Sessions, Skipping Password and 2FA Entirely

Anthropic Warns Infostealer Malware Is Hijacking Claude Accounts by Stealing Login Sessions, Skipping Password and 2FA Entirely
Anthropic told affected Claude users this week that commodity infostealer malware, not any breach of Anthropic's own systems, copied their browser login sessions and replayed them to burn paid usage. The stolen cookies walk straight past two-factor authentication and corporate single sign-on because they represent an already-completed login, and Anthropic still hasn't said how many accounts were hit.

Anthropic has confirmed that a threat actor spent recent weeks hijacking Claude accounts using nothing more exotic than commodity infostealer malware, the same category of malware that has been draining Steam accounts and Discord tokens for years.

The company sent notification emails to affected users describing how attackers were using stolen browser session cookies, not stolen passwords, to access accounts and burn through paid usage. One recipient posted the email to Reddit, and BleepingComputer reported on it August 30.

"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic wrote, according to the notification BleepingComputer reviewed.

Anthropic named six malware families behind the campaign: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer, known as AMOS, on a smaller number of Mac machines, per BleepingComputer and Cyberpress.org. None of the six are new or custom-built. They're rented tools sold on dark web criminal marketplaces, according to thecyberexpress.

Why 2FA and SSO didn't help

Two-factor authentication protects the login page. Once a user passes that check, the site issues a browser cookie so they stay signed in. Infostealer malware copies that cookie directly off an infected machine and hands it to an attacker, who can then replay it and look, to Anthropic's servers, exactly like the legitimate user who already cleared the 2FA check. Help Net Security described this shift on August 31 as "session theft becoming the new credential theft."

SOCFortress put it bluntly in its own writeup: the token itself "serves as cryptographic proof of a completed login," so a password reset alone does nothing if the underlying session is still alive on a compromised machine.

VentureBeat's reporting adds a detail the other coverage mostly skipped over: the accounts Anthropic caught were card-billed, self-serve accounts, the exact population that sits outside any corporate identity provider's control. No IT admin, no matter how good their setup, can revoke a session on an account their organization doesn't govern. VentureBeat noted that Anthropic had not answered, as of publication, how many accounts were affected, whether any Team or Enterprise seats sitting behind SSO were among them, or whether stolen sessions reached conversation history and connected apps beyond just usage limits.

How Anthropic caught it, and what it did

Anthropic said the giveaway was a usage pattern that made no sense: limits refilling and then draining while the account owner wasn't touching Claude, according to BleepingComputer and thecyberexpress. In response, the company is signing affected users out, stripping saved payment methods, and refunding charges it identifies as unauthorized.

Anthropic stressed repeatedly that this isn't a Claude vulnerability. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company wrote, per BleepingComputer. GridinSoft's writeup backs that framing up directly, calling it "an endpoint-malware incident, not evidence that Anthropic's infrastructure was breached."

One affected user, posting as WorriedAssociate7029 according to thecyberexpress, said he'd downloaded a pirated game from a Russian underground forum. "I got fooled like a rookie," he wrote. That same user said he then used Claude's Opus model in what he described as permission-free mode on his own machine to scan for the infection, find the malware, and shut it down. That proved an ironic twist given the malware had been stealing sessions from the same product.

Cyberpress.org additionally reported a separate campaign tracked by security firm Huntress under the name FakeAgent. In late July 2026, Bing searches for the Claude desktop app surfaced sponsored ads linking to a fake installer hosted on a Claude Artifact page, which inherited claude.ai's own SSL certificate and search ranking. That page reportedly logged roughly 7,100 downloads and compromised at least 29 organizations before Anthropic took it down. Cyberpress also described a newer technique involving poisoned SKILL.md configuration files that could reinfect a machine after a full OS reinstall. Those two claims appear only in Cyberpress's reporting and haven't been independently corroborated by the other outlets covering this story.

What's unresolved

Anthropic still hasn't disclosed a total account count, and the company had not responded to VentureBeat's questions about SSO-protected Enterprise accounts as of that outlet's publication. Security researchers at GridinSoft and SOCFortress both note that signing an account out doesn't disinfect the machine that got compromised in the first place, meaning a freshly created Claude session on the same infected computer can be stolen the same way on the next login.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
VentureBeatStolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
unknown
GridinSoft BlogClaude Session Stolen by Infostealer? What to Do
unknown
socfortress.mediumInfostealers Hijack Claude Accounts via Session Theft
unknown
Bleeping ComputerAnthropic warns infostealer malware is hijacking Claude sessions to drain usage
unknown
Cyberpress.orgInfostealer Malware Steals Claude Session Cookies to Hijack Accounts and Bypass 2FA
unknown
socradar.ioAnthropic Links Claude Session Theft to Infostealer Malware
unknown
thecyberexpressAnthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage