Infostealers are hijacking Claude accounts at users’ expense
Brief
Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts.
Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in.
According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the accounts and consume their usage.
“We recently signed you out of Claude and removed the payment method saved on your account, so you’ll need to log back in and re-add your card. We’re sorry for the disruption. Here’s what happened and what we’ve done about it.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
Infostealers are hijacking Claude accounts at users’ expense
Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts.
Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in.
According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the accounts and consume their usage.
“We recently signed you out of Claude and removed the payment method saved on your account, so you’ll need to log back in and re-add your card. We’re sorry for the disruption. Here’s what happened and what we’ve done about it.
What happened
We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage. Our systems detected this activity on your account, and we’ve therefore removed your card on file and signed out the sessions involved to help block further unauthorized access.
If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”
The message adds that Anthropic has no reason to believe the malware was “related to Claude, installed through Claude, or related to anything you did with Claude.”
To sum this up:
- Cybercriminals are spreading infostealers . How they are doing this and whether they are targeting groups likely to use Claude professionally is unknown.
- Infostealers can bypass standard credentials and multi-factor authentication (MFA) by stealing active browser sessions and session cookies.
- Once they are able to take over a Claude account, they can consume the victim’s usage and potentially incur additional charges.
Infostealers are hijacking Claude accounts at users’ expense
Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts.
Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in.
According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the accounts and consume their usage.
“We recently signed you out of Claude and removed the payment method saved on your account, so you’ll need to log back in and re-add your card. We’re sorry for the disruption. Here’s what happened and what we’ve done about it.
What happened
We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage. Our systems detected this activity on your account, and we’ve therefore removed your card on file and signed out the sessions involved to help block further unauthorized access.
If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”
The message adds that Anthropic has no reason to believe the malware was “related to Claude, installed through Claude, or related to anything you did with Claude.”
To sum this up:
- Cybercriminals are spreading infostealers . How they are doing this and whether they are targeting groups likely to use Claude professionally is unknown.
