Security & Risk5 minNewsroom

Anthropic Detects Infostealers Hijacking Claude Sessions and Forces Logout on Affected Accounts

Teclado de notebook iluminado por luz azul de monitor à noite, com ícone de cookie do navegador projetado sobre a tecla enter e caderno aberto com anotação manuscrita sessão revogada

Anthropic has begun logging out Claude accounts, deleting saved payment methods, and refunding charges after identifying malware stealing session cookies and draining paid quotas without going through MFA.

Anthropic has started disconnecting paid users from Claude and refunding unauthorized charges after identifying an anomalous usage pattern across several accounts: quotas were consumed to the limit even when the account owner was not logged in. The investigation pointed to a known family of infostealers stealing already authenticated session cookies from the victim's browser, allowing the attacker to replicate the session without needing a password, TOTP, or SSO.


According to communication sent to affected clients, the identified samples include Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, as well as the Atomic Stealer on macOS. These are well-known vectors that have been around for years, distributed via drive-by downloads, malicious extensions, and cloned installers through SEO poisoning. The novelty is not the malware itself, but how it has learned to monetize. A monthly quota of Claude Pro or Team has turned into a commodity resold in forums, along with an active session and saved payment method.


Anthropic emphasized that there is no indication that the infection originated from within Claude, the website anthropic.com, or any action taken by the user on the product. It is malware present on the customer's machine, capturing browser data before any request reaches the server.


Why the Cookie Defeats the Second Factor


The session cookie is the token that the browser presents to the service to say, "It's me, I've already authenticated." If stolen from the local disk by the infostealer, it can be injected into another browser and reused until it expires. No SMS, TOTP, or Duo push is triggered in the process because no new login occurs. For Claude's backend, it is the same user returning from another machine.


Anthropic's response involves three fronts. The first is to terminate affected sessions server-side, which invalidates the cookie immediately and forces the real account owner to reauthenticate. The second is to remove saved payment methods from the identified accounts, cutting off the subsequent fraud vector. The third is the refund of charges that the team classifies as unauthorized consumption. The company also advised affected users to change their credentials, revoke sessions in other services, and clean their machines before logging back in.


What Changes for the CIO


This incident carries a lesson that goes beyond Claude. Generative AI tools have migrated into the credential vaults of business areas in the past eighteen months. Personal and corporate accounts coexist in the same Chrome browser of the analyst, in the same Safari of the partner. An infostealer on a personal Windows machine captures cookies from LinkedIn, banks, Slack, and now Claude with the same ease.


For the security team, three fronts gain immediate urgency. Endpoint hygiene returns to the top of the agenda, with heightened attention to detecting browser session hijacking in the EDR rule set. The lifespan of session cookies in AI services needs to be shortened, with forced reauthentication when the session migrates from IP, ASN, or device fingerprint. Additionally, the cost per user in AI services should include anomaly alerts similar to those present today for any AWS account or Snowflake API.


The attack scales because an infected endpoint is a ready-made toolkit. Chrome passwords, session cookies from dozens of SaaS, and crypto wallets in a single stealer log are sold in bundles on the dark web for prices that often start in the double digits. What was lacking was a target expensive enough to justify automation at scale. Paid accounts for AI assistants are costly.


The Global Blind Spot


The problem is transnational by nature. In the United States and the United Kingdom, where AI subscription markets are more mature, the density of paid accounts per endpoint raises the expected return from attacks, and abuse tends to appear sooner in provider telemetry. In markets such as India and the Philippines, home to many offshore development centers for global consultancies and banks, the exposure is twofold: corporate machines with Claude for Work licenses coexist with trainee programs that use the accounts outside of business hours and on less monitored networks. In Brazil, the pattern observed by fraud researchers in recent quarters has already shown growth in stealer logs containing corporate SaaS credentials.


The point that Anthropic avoided saying out loud is the one implicitly outlined in their response. Blocking sessions, refunding, and flagging charges work for the current incident. They do not close the door. As long as browsers continue to treat session cookies as portable tokens without additional proof of ownership, the front line of fraud in AI will be this: not breaking into the model, just renting the account of someone who has already paid for it.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk