Anthropic warns Claude users of malware stealing login sessions and draining usage
Anthropic has warned Claude users about infostealer malware that hijacks active browser sessions to bypass security measures like 2FA. The company is taking proactive steps, including signing out affected users and refunding unauthorized charges.
Why it matters
This highlights a growing cybersecurity threat where attackers bypass traditional authentication by stealing session tokens, posing a risk to all web-based AI services.
AI giant Anthropic has issued a warning to Claude users after discovering that infostealer malware is hijacking active login sessions to access accounts and drain usage. According to a report by Bleeping Computers, the company said that the attackers are stealing authenticated browser sessions from infected computers, enabling them to bypass passwords and two-factor authentication. Anthropic is signing affected users out of Claude, removing saved payment methods, and refunding unauthorised chargesWhat Anthropic told affected usersIn an email sent to affected accounts, Anthropic said it recently became aware of a bad actor using common infostealer malware to steal Claude login sessions directly from people's computers, then using those stolen sessions to access accounts and burn through the victims' usage.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in