Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Anthropic Warns Infostealer Malware Is Hijacking Claude Accounts by Stealing Login Sessions, Skipping Password and 2FA Entirely

Anthropic has confirmed that a threat actor spent recent weeks hijacking Claude accounts using nothing more exotic than commodity infostealer malware, the same category of malware that has been draining Steam accounts and Discord tokens for years.
The company sent notification emails to affected users describing how attackers were using stolen browser session cookies, not stolen passwords, to access accounts and burn through paid usage. One recipient posted the email to Reddit, and BleepingComputer reported on it August 30.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic wrote, according to the notification BleepingComputer reviewed.
Anthropic named six malware families behind the campaign: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer, known as AMOS, on a smaller number of Mac machines, per BleepingComputer and Cyberpress.org. None of the six are new or custom-built. They're rented tools sold on dark web criminal marketplaces, according to thecyberexpress.
Why 2FA and SSO didn't help
Two-factor authentication protects the login page. Once a user passes that check, the site issues a browser cookie so they stay signed in. Infostealer malware copies that cookie directly off an infected machine and hands it to an attacker, who can then replay it and look, to Anthropic's servers, exactly like the legitimate user who already cleared the 2FA check. Help Net Security described this shift on August 31 as "session theft becoming the new credential theft."
SOCFortress put it bluntly in its own writeup: the token itself "serves as cryptographic proof of a completed login," so a password reset alone does nothing if the underlying session is still alive on a compromised machine.
VentureBeat's reporting adds a detail the other coverage mostly skipped over: the accounts Anthropic caught were card-billed, self-serve accounts, the exact population that sits outside any corporate identity provider's control. No IT admin, no matter how good their setup, can revoke a session on an account their organization doesn't govern. VentureBeat noted that Anthropic had not answered, as of publication, how many accounts were affected, whether any Team or Enterprise seats sitting behind SSO were among them, or whether stolen sessions reached conversation history and connected apps beyond just usage limits.
How Anthropic caught it, and what it did
Anthropic said the giveaway was a usage pattern that made no sense: limits refilling and then draining while the account owner wasn't touching Claude, according to BleepingComputer and thecyberexpress. In response, the company is signing affected users out, stripping saved payment methods, and refunding charges it identifies as unauthorized.
Anthropic stressed repeatedly that this isn't a Claude vulnerability. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company wrote, per BleepingComputer. GridinSoft's writeup backs that framing up directly, calling it "an endpoint-malware incident, not evidence that Anthropic's infrastructure was breached."
One affected user, posting as WorriedAssociate7029 according to thecyberexpress, said he'd downloaded a pirated game from a Russian underground forum. "I got fooled like a rookie," he wrote. That same user said he then used Claude's Opus model in what he described as permission-free mode on his own machine to scan for the infection, find the malware, and shut it down. That proved an ironic twist given the malware had been stealing sessions from the same product.
Cyberpress.org additionally reported a separate campaign tracked by security firm Huntress under the name FakeAgent. In late July 2026, Bing searches for the Claude desktop app surfaced sponsored ads linking to a fake installer hosted on a Claude Artifact page, which inherited claude.ai's own SSL certificate and search ranking. That page reportedly logged roughly 7,100 downloads and compromised at least 29 organizations before Anthropic took it down. Cyberpress also described a newer technique involving poisoned SKILL.md configuration files that could reinfect a machine after a full OS reinstall. Those two claims appear only in Cyberpress's reporting and haven't been independently corroborated by the other outlets covering this story.
What's unresolved
Anthropic still hasn't disclosed a total account count, and the company had not responded to VentureBeat's questions about SSO-protected Enterprise accounts as of that outlet's publication. Security researchers at GridinSoft and SOCFortress both note that signing an account out doesn't disinfect the machine that got compromised in the first place, meaning a freshly created Claude session on the same infected computer can be stolen the same way on the next login.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.