Security advisory
AI SecurityMediumMitigatedUpdated Sep 1, 2026

Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions

Stolen browser sessions, not a Claude breach, let attackers consume victims' AI usage quotas while they slept.

Emanuel De AlmeidaSep 1, 2026, 12:38 AM5 min read
Severity
Medium
Status
Mitigated
Entity
Anthropic
Confirmed by
Anthropic email to affected users, shared on Reddit

Anthropic is warning some Claude users that infostealer malware already present on their computers stole active Claude login sessions, letting attackers log into accounts and burn through usage limits, according to an email Anthropic sent to affected users and shared on Reddit. The company said it is signing out affected accounts, removing saved payment methods, and refunding charges it identifies as unauthorized.

The incident illustrates how session-cookie theft, not password compromise, is increasingly the entry point attackers use against cloud and AI accounts, since a stolen authenticated browser session can skip login and two-factor checks entirely.

Key takeaways

  • Anthropic says infostealer malware on victims' PCs and Macs stole active Claude login sessions.
  • A stolen session lets an attacker bypass normal password and 2FA login because the browser session is already authenticated.
  • Anthropic identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer (AMOS) on a small number of Macs.
  • Anthropic is signing out affected users, removing saved payment methods, and refunding unauthorized charges.
  • Anthropic stresses the malware is unrelated to Claude and typically arrives through unrelated downloads, such as pirated software.

Affected

Vendors
Anthropic
Products
ClaudeClaude.ai web sessions
Malware
VidarLummaC2StealCRedLineAcreedAtomic Stealer (AMOS)
Geography
Global

What did Anthropic tell affected Claude users?

Anthropic Claude infostealer session hijacking is the pattern Anthropic described in an email sent to compromised account holders: a bad actor used common infostealer malware to steal Claude login sessions from people's computers, then used those sessions to access accounts and consume usage. Anthropic told users that if their usage limits appeared to refill and then drain while they were not using Claude, this was the likely cause.

The company said its investigation is ongoing but that affected computers were likely already infected with general-purpose infostealer malware unrelated to Claude. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," Anthropic wrote, according to the email shared on Reddit and reported by BleepingComputer.

Why session theft bypasses passwords and 2FA

Infostealer malware harvests data stored locally on an infected machine, including browser passwords, login cookies, and credentials for other applications. Because a Claude session is stored as an already-authenticated browser session, a stolen copy of it lets an attacker skip the normal password and two-factor login flow altogether. Anthropic said the malware likely collected the victim's Claude session as one of many items during the initial infection, and that a threat actor later began picking Claude sessions specifically out of that stolen data to use them.

In the case shared publicly, the affected Redditor confirmed downloading a pirated game shortly before the compromise, a common infection vector for infostealers that has nothing to do with Claude's own security.

Which malware families is Anthropic linking to the attacks?

  • Vidar
  • LummaC2
  • StealC
  • RedLine
  • Acreed (Windows)
  • Atomic Stealer / AMOS, identified on a small number of Macs

Anthropic said it has identified these malware families among the infections tied to the session theft. All are established, general-purpose credential and cookie stealers already tracked across the broader threat landscape, not tools built to target Claude specifically.

How is Anthropic responding?

Anthropic said it is signing affected users out of Claude, which revokes the stolen sessions, removing saved payment methods to block unauthorized purchases, and refunding charges it identifies as unauthorized. The company was explicit about the limits of this response: "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," it warned, adding that if the malware remains on a victim's computer, the next login session could be stolen the same way.

What should affected users do now?

  1. Remove the infostealer malware from the affected PC or Mac using a reputable security scan before logging back into Claude.
  2. Change Claude account credentials and any other passwords stored in the same browser.
  3. Revoke other active sessions across Claude and other services that shared the infected browser.
  4. Avoid installing pirated software or unverified apps, a common infection route Anthropic cited in the case it addressed.

Why this matters beyond Claude

The incident is a reminder that AI subscription accounts carry real monetary value attackers can quietly siphon through usage-based billing, not just data theft. Because infostealers operate independently of the service they eventually target, IT teams should treat any AI or SaaS account tied to a compromised endpoint as at risk, regardless of whether that endpoint ever ran the vendor's own software. Session-cookie theft has become a preferred technique precisely because it sidesteps password resets and MFA enforcement that organizations rely on as their primary defense.

Timeline

Anthropic emails affected usersAnthropic sent an email to compromised account holders explaining that a bad actor used common infostealer malware to steal Claude login sessions and consume usage, according to a copy shared on Reddit.

Impact & actions

Infostealer-hijacked Claude sessions let attackers consume victims' usage allotments and rack up charges without ever triggering a password or 2FA prompt.

Security: The underlying infostealer infections predate and are unrelated to Claude, meaning session theft is a symptom of broader endpoint compromise via malware like Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer.

Privacy: Infostealers that harvested Claude sessions typically also collect saved browser passwords and other app credentials from the same infected machine.

Recommended actions · Medium urgency

  1. 1Run a full malware scan and remove any infostealer found before logging back into Claude
  2. 2Change the Claude account password and revoke other active sessions after cleaning the device
  3. 3Avoid pirated software and unverified downloads, the most common infostealer delivery route cited in this case
  4. 4Review Claude billing history for unauthorized charges and confirm any refunds from Anthropic

Technical details

Exploitation
Exploited in the wild
Attack vector
Local infostealer malware on a victim's Windows PC or Mac harvests browser data, including already-authenticated Claude session cookies, which an attacker then reuses to log into Claude accounts without a password or 2FA.

Mitigations

  • Anthropic revokes compromised Claude sessions and removes saved payment methods on affected accounts
  • Run reputable anti-malware software to detect and remove infostealers such as Vidar, LummaC2, StealC, RedLine, Acreed, or Atomic Stealer

Response

Vendor

Anthropic told an affected user in an email that it is aware of a bad actor using common infostealer malware to steal Claude login sessions and use them to access accounts and consume usage, and stressed the malware is unrelated to Claude itself.

Customer guidance

Anthropic advises affected users that signing them out stops the stolen session but does not remove the malware, and urges changing credentials, revoking other sessions, and cleaning the infected computer before logging back in.

FAQ

How did attackers hijack Claude accounts without a password?

Infostealer malware already on victims' computers copied active, authenticated Claude browser sessions, letting attackers reuse the login directly and skip the password and 2FA process entirely.

What malware is Anthropic linking to the Claude session theft?

Anthropic identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows machines, plus Atomic Stealer (AMOS) on a small number of Macs.

Is the infostealer malware related to Claude or delivered through it?

No. Anthropic said it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything the user did with Claude; infections typically come from unrelated downloads like pirated software.

What is Anthropic doing for affected users?

Anthropic is signing affected accounts out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.

How would a user know their Claude account was hijacked this way?

Anthropic said a telltale sign is usage limits appearing to refill and then drain even when the account owner was not using Claude.

What should someone do if their Claude session was stolen?

Anthropic recommends removing the infostealer from the infected computer, changing the Claude password, and revoking other active sessions before logging back in.

The bottom line

Anthropic emailed affected Claude users to explain that pre-existing infostealer malware stole authenticated login sessions, letting attackers access accounts and drain usage without passwords or 2FA.

What happens next

Anthropic said its investigation is ongoing, and it continues to revoke compromised sessions, strip saved payment methods, and refund unauthorized charges as more affected accounts are identified.

What to do

If your Claude usage looks like it drained unexpectedly, scan your device for infostealer malware, remove it, then change your Claude password and revoke other sessions.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles