Skip to content

Monday, August 31, 2026

Gigantum.net
Artificial intelligence

Anthropic has a warning for Claude users: We have recently seen some ...

Tech News News: AI giant Anthropic has issued a warning to Claude users after discovering that infostealer malware is hijacking active login sessions to access accoun.

· 584 words· updated August 31, 2026 at 03:12 AM

AI giant Anthropic has issued a warning to Claude users after discovering that infostealer malware is hijacking active login sessions to access accounts and drain usage. According to a report by Bleeping Computers, the company said that the attackers are stealing authenticated browser sessions from infected computers, enabling them to bypass passwords and two-factor authentication. Anthropic is signing affected users out of Claude, removing saved payment methods, and refunding unauthorised chargesWhat Anthropic told affected usersIn an email sent to affected accounts, Anthropic said it recently became aware of a bad actor using common infostealer malware to steal Claude login sessions directly from people's computers, then using those stolen sessions to access accounts and burn through the victims' usage. The email, which was shared publicly on Reddit by one affected user, also gave people a way to recognise the symptom: if a Claude account's usage limits appeared to refill and then mysteriously drain while the account wasn't actively being used, that pattern was likely the cause.The mechanics of the attack make it particularly hard to notice. Infostealer malware can copy an already-authenticated browser session, meaning an attacker doesn't need to go through a normal password or two-factor authentication login process to gain access — they simply reuse a session that's already been verified.The malware behind the attacksAnthropic said its investigation is still ongoing, but that affected computers were most likely already infected with general-purpose infostealer malware unrelated to Claude itself. The company was explicit on this point, stating it has no reason to believe the malware is connected to Claude, was installed through Claude, or relates to anything the user did within the Claude platform.According to Anthropic, this type of malware typically spreads through downloads or malicious apps, and once installed, harvests information stored locally on a device — including browser passwords, login cookies, and credentials tied to a wide range of other apps and services. A user's Claude session was likely just one of many pieces of data swept up in that broader collection process, with attackers only recently beginning to specifically extract and exploit the Claude sessions from what they'd already gathered.In the case shared on Reddit, the affected user confirmed they had downloaded a pirated game shortly before the compromise, offering a likely explanation for how the malware ended up on their system in the first place.Anthropic said it has identified several specific malware families involved in these attacks, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows systems, along with Atomic Stealer (AMOS) affecting a small number of Mac users.How Anthropic is respondingFor accounts identified as compromised, Anthropic is taking several protective steps: signing affected users out of Claude, revoking the stolen sessions, removing any saved payment methods from the account, and refunding charges it identifies as unauthorized.However, the company was clear that this response only addresses the symptom, not the underlying cause. Anthropic warned that signing a user out stops the stolen session from being used, but it doesn't remove the malware itself — meaning if the infection is still present on a user's device, their very next login session could be stolen through the exact same method.What Anthropic is telling users to doAnthropic has urged affected users to take basic follow-up security steps beyond what the company can do on its end, including changing their account credentials, revoking any other active sessions tied to their accounts, and thoroughly removing the malware from their infected computers before logging back in.Get the latest technology news and updates. Download the TOI App.

Gathered from external sources. Rights to this text belong to whoever originally published it.