Skip to content
Anthropic warns Claude users after infostealers hijack active login sessions

Anthropic warns Claude users after infostealers hijack active login sessions

Firstpost August 31, 2026

Anthropic has begun alerting Claude users whose active login sessions were reportedly stolen by infostealer malware. The company says attackers are using those sessions to access accounts and burn through usage limits, while affected users are being signed out and having saved payment methods removed.

Some Claude users are being forced to log back into their accounts after Anthropic discovered that attackers were using stolen browser sessions to access the AI service and consume account usage.

According to several reports, the company has started contacting people whose Claude sessions appear to have been compromised. Anthropic says it has found evidence that common infostealer malware, rather than a vulnerability in Claude itself, was responsible for obtaining the sessions from infected computers.

The warning is particularly relevant to users who noticed their Claude usage limits behaving unusually. According to Anthropic, accounts where usage appeared to reset before being rapidly exhausted may have been accessed by someone else.

The company is responding by revoking compromised Claude sessions, signing affected users out and deleting saved payment information. Anthropic also says it will refund charges that its investigation determines were unauthorised.

The issue came to wider attention after an affected user posted Anthropic's warning on . The user said they had downloaded a pirated game before discovering that their computer had been compromised, offering a possible explanation for how the malware reached the machine.

Infostealers are designed to harvest information already stored on a computer. That can include browser passwords, authentication cookies and credentials associated with other applications. An attacker who obtains an active authenticated session may not necessarily need the victim's password or a fresh two-factor authentication check to gain access.

Anthropic says this appears to be what happened with the affected Claude accounts. The company believes the malware first collected a wide range of information from infected machines, after which an attacker selectively extracted Claude sessions and began using them.

Anthropic has identified several Windows-based infostealers in its investigation, including Vidar, LummaC2, StealC, RedLine and Acreed. It also found Atomic Stealer, commonly known as AMOS, on a small number of Mac computers.

The company has stressed that there is currently no indication that the malware originated from Claude or was installed through the service. Instead, the infections are believed to have come from malicious applications or downloads.

Anthropic's immediate account-level measures can stop an attacker from continuing to use a stolen Claude session, but they cannot clean an infected computer.

"Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," the company warned affected users.

That distinction is important because logging back into Claude from the same compromised machine could create another stolen session.

Anthropic is therefore advising affected users to remove the malware from their computers, change relevant credentials and revoke other active sessions. Users should also take care when downloading software, particularly applications obtained from unofficial sources.

The investigation remains ongoing, and Anthropic has not indicated how many accounts have been affected. For now, the company's findings point to a broader endpoint-security problem rather than a compromise of Claude's own infrastructure.