in

Anthropic Signs Out Claude Users After Malware Steals Login Sessions

Anthropic has started signing Claude users out of their accounts after discovering that infostealer malware running on their own computers had copied their active Claude login sessions. Attackers then replayed those stolen sessions to get into paid accounts and burn through the subscription usage the account holder had paid for. The company says it has revoked the compromised sessions, stripped saved payment methods off the affected accounts, and refunded charges it could confirm were unauthorised.

The warning went out by direct email rather than a public post, so most people only heard about it when an affected user posted the notice on Reddit. That email is the primary document behind every report on this.

Hosting 75% off

What Anthropic actually said

“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the company wrote in the notice, as reported by BleepingComputer. It also gave users a way to recognise whether they were hit: “If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”

The malware families named so far are Vidar, Lumma (also written LummaC2), StealC, RedLine and Acreed on Windows, plus Atomic Stealer, known as AMOS, on a small number of Macs. These are commodity infostealers sold on criminal forums for years, and they scoop up everything they can reach on an infected machine: saved browser passwords, login cookies, and credentials belonging to other local apps.

Anthropic was explicit that the infection did not come from its own product. “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,” the company said, adding that phones and tablets do not appear to have been involved. The user who published the email traced their infection to a pirated game.

Why a stolen cookie beats two-factor authentication

Two-factor authentication protects the moment you log in. After that, the site hands your browser a session cookie so you are not asked to re-authenticate on every click. An infostealer copies that cookie. An attacker who replays it is treated by the service as somebody who already passed the password check and the 2FA check, because from the server’s point of view, that is what happened.

So 2FA did its job here and was still irrelevant. As Help Net Security put it, session theft has effectively become the new credential theft. Anthropic made the same point about the limits of its own fix: “Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware. If it’s still on your computer, your next login session could be stolen the same way.”

The bit that matters if you work online for a living

If you sell services online, your machine holds live sessions for far more than a chatbot. Upwork or Fiverr. Your client’s WordPress admin. Payoneer or Wise. Your email. Drive folders full of client files. A hosting control panel. Every one of those is held open by the same kind of cookie that got lifted here, and an infostealer does not care which of them it grabs.

Losing a month of Claude usage is annoying. Losing a client’s site or your withdrawal account is a different order of problem, and it damages a reputation you spent years building.

The infection route in the reported case is the familiar one: an unofficial download. Cracked software, nulled WordPress plugins and themes, patched desktop apps, pirated games. Where paid tools feel expensive relative to local income, that temptation is real and widely acted on, and this incident illustrates the price. If you are weighing which tools are worth paying for, our guide to AI tools for freelancers covers the ones that earn their subscription.

The clean-up order Anthropic recommends

Sequence matters, because doing these steps out of order wastes the effort. Remove the malware first, since any password you change while the machine is still infected gets stolen again. After that, Anthropic advised setting a new password and enabling 2FA on the email account tied to Claude, updating passwords saved in browsers, and checking card statements if payment details were stored there. Beyond Claude, sign out of active sessions on your other services and log back in, which invalidates any cookies stolen earlier.

Expect fake “Anthropic security notice” emails as a follow-up, since the real notice arrived by email and that is exactly the cover a copycat needs. Do not act on links in any such message. Go to the service directly and check the account there.

Still unresolved

Anthropic says its investigation is ongoing, and it has not published a figure for how many accounts were drained or how much unauthorised spend was refunded. Nor has it said how it tells a hijacked session apart from ordinary heavy use, a detail that matters to anyone who has hit a usage cap and wondered why.

The broader question is whether AI subscriptions are becoming a standard resale item on the infostealer market the way streaming and gaming accounts already are. A paid AI plan with high limits has obvious resale value, the credentials already sit in stolen data dumps, and this campaign shows somebody worked out how to sort them out of the pile.

Hosting 75% off

Written by Hajra Naz

Hackers Are Targeting Your Money and Data With More Phishing Attacks

Hackers Are Targeting Your Money and Data With More Phishing Attacks

OpenAI Cuts Cursor Off From Its Models After SpaceX Buys the Company