Anthropic Warns Infostealer Malware Is Hijacking Claude Accounts to Drain Usage
Anthropic is notifying a number of Claude users that infostealer malware on their computers stole active Claude login sessions, which attackers then used to access those accounts and consume victims’ usage without their knowledge. The company began signing out affected users, removing saved payment methods, and refunding unauthorized charges after identifying the pattern.
What Anthropic Told Affected Users
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” Anthropic said in an email sent to affected users, one of whom shared the message on Reddit, according to BleepingComputer. “If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause,” the company warned.
Anthropic was direct in the email about the fact that its own product wasn’t the source of the compromise. “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,” the company stated, according to BleepingComputer. Anthropic said the affected computers were likely already infected with general-purpose infostealer malware before any Claude-specific activity occurred, and that a bad actor subsequently began specifically picking Claude sessions out of the larger pool of credentials the malware had already collected.
How the Attack Actually Works
Infostealer malware is designed to quietly extract locally stored information from an infected computer — including browser passwords, login cookies, and credentials for other applications — and send that data back to the people who deployed it, according to Search Engine Journal. Unlike ransomware, which announces itself by locking files and demanding payment, infostealers are built to remain undetected for as long as possible in order to maximize the amount of valuable data they can collect.
The specific mechanism at play here involves session hijacking rather than a traditional credential theft. According to a technical breakdown from MeetCyber, the attack chain runs from malicious download to infostealer infection, then session cookie theft, session replay, and finally unauthorized Claude account access and usage. Because the malware can copy an already-authenticated browser session, an attacker doesn’t necessarily need a victim’s actual password or two-factor authentication code — reusing a valid session token can be sufficient to bypass those normal login protections entirely.
Which Malware Strains Are Involved
According to BleepingComputer, Anthropic identified several specific infostealer variants behind the compromised sessions: Vidar, LummaC2, StealC, RedLine, and Acreed, all of which primarily target Windows systems. A smaller number of Mac users were affected by a different strain, Atomic Stealer, according to News4Hackers’ coverage of Anthropic’s disclosure.
What Anthropic Has Done in Response
Once the pattern was identified, Anthropic began signing affected users out of their Claude sessions across all devices and removing the payment methods saved on their accounts, according to Search Engine Journal. Because a Claude login session is stored locally on a user’s device, signing a user out effectively cancels that session everywhere at once — which is why affected users needed to log back in across all of their own devices after the action was taken. The company said it is also processing refunds for any charges it identifies as unauthorized as part of the response.
According to News4Hackers, the breach was identified through a combination of user reports and Anthropic’s own internal investigations, and the company’s analysis is ongoing.
What Anthropic Is Advising Affected Users to Do
Beyond the account-level actions Anthropic itself has taken, the company advised affected users to take additional steps on their own end to fully secure their accounts, according to News4Hackers: changing credentials, revoking all active sessions manually, and removing the underlying malware from their infected devices. Anthropic specifically warned that simply being signed out by the company wasn’t sufficient on its own — if the infostealer malware remains active on a user’s system, it could continue stealing new session data and lead to repeated compromise even after the initial remediation.
Why This Matters Beyond Anthropic Specifically
Security researchers characterized this incident as part of a broader, growing pattern rather than something unique to Claude. According to MeetCyber’s analysis, the underlying vulnerability — infostealer malware harvesting authenticated session tokens rather than passwords — represents an increasingly common attack vector across AI services and enterprise software generally, since session hijacking can bypass even relatively strong account security measures like two-factor authentication once a device itself has already been compromised by malware unrelated to the specific service being targeted.
FAQ
How did attackers gain access to victims’ Claude accounts? Through infostealer malware already present on victims’ computers, which stole active, already-authenticated Claude login sessions rather than passwords, allowing attackers to reuse those sessions to access accounts directly.
Which malware was responsible? Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows systems, and Atomic Stealer on a smaller number of Mac systems.
Was Claude itself the source of the compromise? No. Anthropic stated it has no reason to believe the malware is related to Claude, installed through Claude, or connected to anything users did within Claude — the malware infected users’ computers independently and then began targeting Claude sessions specifically.
What has Anthropic done for affected users? Signed them out of Claude across all devices, removed saved payment methods from their accounts, and is processing refunds for charges it identifies as unauthorized.
What should affected users do beyond what Anthropic has already done? Change their credentials, manually revoke all active sessions, and remove the underlying infostealer malware from their devices, since residual malware could lead to repeated session theft even after being signed out.
Conclusion
This incident illustrates a security challenge that extends well beyond any single company: as more services rely on persistent, cookie-based login sessions for convenience, infostealer malware capable of harvesting those already-authenticated sessions can bypass password and two-factor protections entirely. Anthropic’s response — signing out affected accounts, removing payment data, and issuing refunds — addresses the immediate account-level exposure, but the underlying malware infections on victims’ own devices remain a separate problem users need to resolve directly to prevent further compromise, whether of Claude or any other service using similar session-based authentication.
Sources: BleepingComputer, Search Engine Journal, MeetCyber, News4Hackers, We Fix PC, OffSeq Threat Radar (reporting dated August 30-31, 2026).
