Hackers do not necessarily need your Claude password to take over your account. A stolen authenticated session may be enough.
Anthropic says infostealer malware has been used to capture active Claude sessions from victims’ devices, allowing attackers to access accounts and consume paid usage. In some cases, unauthorized activity can also trigger additional charges when usage credits or automatic reloads are enabled.
The company told affected users that the attacks appear to involve externally acquired malware rather than a vulnerability in Claude itself, according to TechCrunch. The incident highlights a growing security problem around AI accounts: an authenticated session can be valuable not only because it grants access, but because it may also carry paid usage and connections to other tools.
How Claude’s usage spike surfaced an attack
The first signs did not come from a security alert or an obvious account takeover. Instead, a Claude user, Grant De Swardt, who is an independent AI consultant in the U.K., began noticing something strange: his usage limits were climbing even when he wasn’t actively using the service.
At one point, his usage rose from 45% to 55% despite him deliberately stopping the Claude-related services he was running, prompting him to investigate and eventually reach out to Anthropic.
Anthropic subsequently told De Swardt that a compromised Claude session key had been used to create unauthorized Claude Code OAuth tokens.
While De Swardt claimed he wasn’t compromised, he also was not the only user to report unexplained activity. Other Claude subscribers on Reddit described usage jumping sharply while they were barely using the service, including one user who reported reaching 49% usage in roughly 12 minutes.
Anthropic points to infostealer malware, not a Claude flaw
Anthropic told TechCrunch that its investigation indicates the unauthorized activity stems from infostealer malware on users’ devices rather than a vulnerability specific to Claude.
Infostealers are designed to collect valuable data from infected systems, including passwords, browser cookies, authentication sessions, and other credentials. Stolen session data can be especially useful because it may let an attacker enter an already authenticated account without going through the normal login process.
Beyond Anthropic, this also suggests the issue may not be isolated to Claude users, meaning attackers may be targeting AI subscribers across different providers, particularly those whose work revolves around heavy AI usage, like De Swardt.
Anthropic responded to affected accounts by signing users out, invalidating existing sessions, and issuing reimbursements in some cases. TechCrunch reported that De Swardt received £44.49, or about $60, back from the remaining balance of his $200 subscription.
Here is how to stay safe
Infostealer malware is not limited to stealing AI account sessions. This malware can also harvest passwords, browser cookies, authentication sessions, and other credentials.
That makes unusual account activity like sudden usage spikes, unfamiliar logins, unexpected password-reset emails, or purchases you did not make worth looking into.
For AI users, the cost of stolen access is harder to ignore as premium AI subscriptions and usage credits get more expensive. But token consumption may be the least serious consequence. If an attacker with access to your AI account uses it for abusive or illegal activity, it could create reputational, financial, or even legal problems for the account owner.
For enterprises investing heavily in AI, that risk becomes even more significant. A compromised employee account could allow access not just to AI tokens, but to business data or other connected tools, turning a stolen session into a much bigger security problem.
Taken together, the Claude attacks show why account security should extend beyond passwords.
For organizations, that makes stolen AI sessions a broader access-control problem rather than simply a billing issue. The unauthorized token usage may be visible first, but the more important question is what else the compromised account was able to reach.
Other news: Check Point researchers uncovered a ChatGPT flaw that let attackers secretly run tasks in a victim’s session and retrieve connected Gmail data through a cross-account channel without stealing a password.





