Anthropic is alerting users that threat actors are deploying commodity infostealer malware to hijack active, authenticated browser sessions, giving hackers unauthorized access to paid Claude accounts.
According to customer notices sent by the Claude Team, attackers are not guessing passwords or exploiting vulnerabilities in Anthropic’s infrastructure. Instead, general-purpose malware running locally on victims’ machines extracts stored browser cookies and session IDs. Because these cookies represent an already-authenticated state, attackers can bypass multi-factor authentication (MFA) and access accounts unnoticed.
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” Anthropic wrote in an advisory sent to affected customers.
The company clarified that its own software remains secure. “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,” the notice stated.
Anthropic identified several common malware strains active in this campaign:
- Windows: Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed
- macOS: Atomic Stealer (AMOS)
Users typically notice the compromise when usage quotas mysteriously fluctuate. As Anthropic explained, “If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”
What affected Claude users should do
This isn’t really a Claude security failure — it’s a reminder of how fragile browser-based logins have become. Session-hijacking malware doesn’t need to crack a password or beat two-factor authentication; it just steals the cookie that proves you already logged in, which many browsers keep sitting in plain reach.
That’s what makes this campaign notable: it shows attackers increasingly treating AI subscriptions like any other stealable commodity, worth draining for resale or personal use, alongside banking and email credentials.
To contain the threat, Anthropic has forcefully signed affected accounts out of all active sessions, revoked stolen tokens, deleted stored credit cards on file, and applied refunds for unauthorized charges.
However, the company warned that platform-side lockouts only treat the symptom: “Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware. If it’s still on your computer, your next login session could be stolen the same way.”
Anthropic recommends that impacted users:
- Run a full malware scan using Microsoft Defender or macOS security utilities.
- Secure linked primary email accounts with new passwords and fresh 2FA keys.
- Revoke all active Google and browser sessions from secondary devices.
- Re-enter payment details only after confirming the local machine is clean.
The bigger security lesson
The incident shows why securing an AI account is increasingly about protecting the device and browser session, not just the password.
For businesses that use AI services extensively, a compromised session could burn through usage allowances before anyone notices. The tradeoff is that stronger account protections alone cannot eliminate the risk if malware has already gained access to an authenticated device.
Anthropic’s decision to revoke sessions and remove stored payment methods limits the immediate damage, but users still need to remove the underlying malware.
Also read: See how malicious ChatGPT extensions can hijack user sessions and expose sensitive AI account data.





