Back Darkreading Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Anthropic proactively signed an unknown number of users out of Claude after a threat actor stole their login sessions, accessed their accounts, and consumed their allotted usage.
The attacks came to light via email alerts sent to affected users that were then posted to social media . The theft of login sessions and unauthorized access to Claude accounts resulted from infostealer malware on users' systems, rather than from any malware related to or installed through Claude, Anthropic said in the email notifications.
Claude Accounts Under Attack
The AI company said it had signed affected users out of Claude and removed their saved payment methods after detecting suspicious activity on their accounts. Anthropic's ongoing investigation has found that the threat actor stole Claude login sessions using general-purpose infostealers that had previously been installed on users' systems, likely through a malicious app or unofficial download.
Related: Hundreds of OpenAI Agents Invaded Hugging Face Servers
“The malware identified in this campaign so far include Vidar , Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs,” Anthropic said in its email to affected users. It's likely that affected users have had the infostealers on their system for some time, the company noted.
The Anthropic incident is another example of attackers shifting from stealing passwords to targeting session cookies and authentication tokens. With many organizations implementing stronger password security protocols and multifactor authentication (MFA), traditional credential theft has become harder, so attackers have increasingly begun targeting session artifacts to hijack already-authenticated sessions and bypass MFA altogether.
Experts have described the shift as complicating incident response because resetting a password alone may not cut off an attacker who already has a valid session or refresh token. In Anthropic's case, for instance, infostealers harvested Claude sessions, likely along with other sensitive information such as login cookies, saved passwords and credentials for other apps. The stolen Claude sessions allowed the attackers to access the associated accounts without having to defeat the authentication controls protecting them.
As one user, who posted Anthropic's email communication on noted, "The hacker stole all my Google Chrome credentials, including cookies and session IDs, which allowed him to bypass all two-factor authentication security measures."
Anthropic did not respond to a Dark Reading request for on the reported account attacks.
Related: Russian Hackers Phish EU Officials Over Messaging Apps
Invalidated Claude Sessions
Anthropic said signing affected users out of their Claude accounts invalidates the sessions that attackers had used to access them. Users would therefore need to log in again on their devices to regain access to Claude. The company also removed all saved payment information associated with compromised accounts, preventing threat actors from using those payment methods to incur additional charges for Claude usage .
In cases where threat actors had already used an affected user's payment card to pay for Claude usage, Anthropic said it had refunded the unauthorized charges. It's unclear what the threat actor used the compromised Claude accounts for.
Anthropic's email cautioned users that its decision to sign affected users out of their Claude accounts only invalidated the stolen sessions. Affected users would still need to remove the infostealer from their systems to prevent the attacker from stealing and misusing their session information once again.
"After the malware has been completely removed, secure the email account you use for Claude by setting a new password, signing out of other devices and enabling two-factor authentication," the notification said.
Related: Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Anthropic's email also advised affected users to consider updating other saved passwords in their browsers like those associated with their work, bank accounts and other apps. It is only after users have completed these steps that they should add a payment method back to their Claude accounts.
Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.
Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.
Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.
His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach
How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach
Cloud Incident Response: Forensics in Distributed Environments
Cloud Incident Response: Forensics in Distributed Environments
Beyond the Login: Key Considerations for Evaluating Identity Security
Beyond the Login: Key Considerations for Evaluating Identity Security
SASE Pivot and Trends 2026: A Gartner Keynote
SASE Pivot and Trends 2026: A Gartner Keynote
What Every Enterprise Should Know Securing Cloud Assets In the Age of AI
What Every Enterprise Should Know Securing Cloud Assets In the Age of AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
