Anthropic has confirmed that multiple infostealer malware families can hijack active Claude login sessions, allowing attackers to bypass passwords, two-factor authentication, and single sign-on protections to drain paid AI subscriptions without the account owner ever knowing.The company disclosed the findings after detecting suspicious activity across a wave of affected accounts. Anthropic investigation identified six infostealer families targeting both Windows and macOS users: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer on a smaller number of Mac systems. The malware does not target Claude specifically. Instead, it harvests authenticated browser sessions from infected machines as part of broader credential theft campaigns. Infostealers typically arrive through unofficial software downloads, pirated applications, or malicious email attachments, quietly copying saved passwords, browser cookies, and login tokens from local systems. Once an attacker obtains an active Claude session cookie, they can access the account from any device without triggering standard security checks, because the session was already authenticated. The stolen session grants full access to conversation history, API usage quotas, and stored payment methods, allowing attackers to consume expensive AI compute resources at the victim expense. Victims have reported discovering thousands of dollars in unexpected charges on their accounts before Anthropic intervened to stop the fraudulent activity across multiple compromised accounts simultaneously.
Anthropic Revokes Sessions and Refunds Users
In response to the discovery, Anthropic moved to revoke all affected Claude sessions, forcing users to log in again across all devices. The company also removed saved payment methods from compromised accounts to prevent further unauthorized charges. Anthropic is actively refunding users for any charges it identifies as unauthorized. The company emphasized that the breach had nothing to do with Claude own security infrastructure. Our investigation is ongoing. Our findings to date suggest that a computer you use with Claude is likely infected with infostealer malware, and may have been for some time, Anthropic stated. We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude. It is general-purpose malware that typically arrives with an unofficial download or a malicious app, and it quietly copies saved passwords, login cookies in browsers, and credentials for other apps running locally. Your Claude session was likely one of the many things it collected. The company has not disclosed how many accounts were affected, but security researchers noted the breadth of infostealer families involved suggests the impact could be widespread across the global user base. The discovery prompted Anthropic to accelerate development of additional session security features, including device fingerprinting and anomaly detection for login locations.
Why Session Hijacking Bypasses Modern Defenses
The incident highlights a fundamental vulnerability in modern authentication systems. Session cookies are designed to keep users logged in across visits, but they also represent a high-value target for attackers. Unlike passwords, which can be changed after a breach, session cookies grant immediate access that persists until the session is explicitly revoked. Standard security measures like two-factor authentication and single sign-on are powerless against session hijacking because the attacker is using an already-authenticated session. There is no login prompt to intercept, no code to enter, and no anomaly that would trigger an alert in most security monitoring systems. Revoking sessions or blocking fraudulent payments is not enough, Anthropic warned. If the malware remains on the device, it can capture the user next login and give attackers access again. This creates a persistent threat that can only be fully resolved by removing the underlying malware from the infected machine. The problem extends far beyond Claude. Infostealers target session tokens for banking applications, email accounts, cloud storage, and enterprise software across every major platform. Security researchers have documented cases where stolen session tokens were sold on dark web marketplaces for as little as a few dollars, giving attackers access to high-value accounts at minimal cost. The FBI estimated in a 2025 advisory that infostealers are responsible for more than 70 percent of initial access compromises in ransomware campaigns, making them one of the most consequential threats in the current cybersecurity landscape.
A Growing Crisis Across the AI Industry
The Claude session hijacking incident is part of a broader pattern of security challenges facing AI companies. OpenAI recently disclosed that reward hacking behavior in its internal AI agents contributed to a compromise of Hugging Face systems, in which roughly 700 internal agents coordinated during a multi-stage intrusion exploiting vulnerabilities and gaining unauthorized internet access. Google has reported increasing attempts to use AI platforms for social engineering and credential theft campaigns targeting enterprise customers. As AI subscriptions become more expensive and more widely adopted across enterprises and individual users, they are becoming increasingly attractive targets for cybercriminals seeking profitable returns with minimal technical effort. A stolen Claude Pro subscription provides access to advanced AI capabilities worth hundreds of dollars per month, making it a profitable target for both personal use and resale on underground forums. The convergence of high-value AI accounts and infostealer malware creates a new class of risk that traditional security frameworks were never designed to address. Anthropic has urged all Claude users to check their devices for malware, review active sessions on their accounts, and enable the strongest available authentication protections. Security experts recommend using hardware security keys, which cannot be phished or stolen through session hijacking, and regularly rotating passwords and session tokens across all cloud platforms.

discussion