Skip to content
Anthropic warns Claude users they may have malware on their PCs

Anthropic warns Claude users they may have malware on their PCs

Thehansindia August 31, 2026

Anthropic has begun sending warnings to Claude users who may have malware on their PCs. The company notes that an attacker could have gained access to their Claude accounts and exhausted their usage limits.

Anthropic appears to have detected that some Claude users may have malware on their PCs or laptops. This malware, known as an "infostealer" (information stealer), allows an attacker to access all of a user's information and account details. In this instance, it could also allow them to use the victim's Claude account.

The AI startup has sent warnings to some Claude users who may have the infostealer malware on their devices. This could have allowed an attacker to access Claude accounts and deplete usage limits. The company is logging affected users out of Claude and removing saved payment methods. Users may also receive refunds for charges that Anthropic identifies as unauthorised.

Anthropic states that Claude itself is not linked to this attack

A user with the handle WorriedAssociate7029 shared the email they received from Anthropic on the ClaudeAI subreddit.

In the email, Anthropic reported that it had recently become aware of a "malicious actor" using common infostealer malware to steal Claude login sessions from people's computers and subsequently use those sessions to access accounts. The company explained that this was likely the cause of the unusual activity on their Claude accounts. "If you noticed your usage limits replenishing and then depleting while you weren't using Claude, this was likely the cause," the email stated.

Anthropic states that while it is investigating the incident, it is likely that only computers were affected by the infostealer malware. "It does not appear that phones and tablets were involved," the company declared. "We have no reason to believe that this malware is related to Claude, was installed via Claude, or has any connection to your activities on Claude."

"Infostealer" malware typically arrives via unofficial downloads or malicious applications and silently copies saved passwords, browser login cookies, and locally stored credentials from other applications. This can even allow an attacker to bypass two-factor authentication and access your accounts. The company noted that a user's Claude session was likely one of many items harvested by the malware, and that attackers had begun selecting and using such sessions. Anthropic indicated that the malware identified so far in the campaign includes Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (or AMOS) on a small number of Mac computers.

What can you do if you have been affected?

If you are among the affected users, Anthropic clarifies that logging out of Claude does not remove the malware. "If it remains on your computer, your login session could be stolen in the same way," the company noted.

Anthropic advises users to scan their computers for malware before using them again and, subsequently, to secure the email account linked to Claude by setting a new password, logging out of other devices, and enabling two-factor authentication. The company also suggests updating other passwords—including those for banking, work, and cloud services—and reviewing card statements if payment details were stored in the browser. Only after completing these steps, the company indicates, should you add a payment method again.

This incident occurs amidst growing debate regarding the future of cybersecurity. Although the use of information-stealing malware (‘infostealers’) is a common tactic, there is concern the potential for increased hacking attempts in the future as AI models become more advanced. Recently, OpenAI revealed that approximately 1,200 AI agents exhibited anomalous behaviour; of these, 700 attempted to hack Hugging Face during an evaluation test. Meanwhile, Anthropic and Meta have also recently reported incidents in which their AI agents acted in unexpected or improper ways.

Kahekashan is a passionate technophile with a keen eye for cutting-edge gadgets, emerging technologies, and everything in the digital realm. Raised in a Defence family with strong values and a background in literature, she has consistently pursued excellence in every endeavour. Her last full-time assignment involved content writing with the Indian School of Business.