Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Anthropic forcibly signed out Claude users and removed stored payment methods after detecting infostealer malware stealing session tokens to consume credits at victims' expense. The operation, carried out between late August and early September 2026, affects Windows customers and a minority of Mac users, with infections originating from pirated software distributed on underground forums. At the same time, September 2026 is shaping up as another record month for Microsoft security patches, confirming a trend of vulnerabilities outpacing organizations' ability to remediate them immediately.
- Infostealers Vidar, Lumma, StealC, RedLine, Acreed (Windows) and Atomic Stealer/AMOS (Mac) stole Claude session tokens, enabling access without credentials
- Anthropic signed users out, removed payment methods, and refunded unauthorized charges, but the malware persists on infected systems
- At least one user traced the infection to downloading a pirated game from a Russian underground forum
- August 2026 recorded the second-largest Patch Tuesday in history with 398 CVEs addressed, of which only 1 was confirmed as actively exploited
How Session Tokens Become Currency
The malware identified in the campaign — Vidar, Lumma (LummaC2), StealC, RedLine, Acreed on Windows, Atomic Stealer (AMOS) on Mac — operates with a well-established mechanism: they extract cookies and session tokens from compromised browsers, not credentials. This distinction is technically decisive. A valid session token lets an attacker impersonate the authenticated user without ever touching passwords or 2FA flows, rendering the intrusion invisible to many traditional perimeter defenses.
Help Net Security, which tracked the phenomenon, frames it as: "Session theft is the new credential theft, as it allows attackers to sidestep two-factor authentication." Anthropic confirmed in its user communication that the malware is unrelated to Claude, not installed via the service, and does not depend on use of the platform: these are pre-existing infections on devices that find in consumption-based AI services a secondary monetization opportunity.
The infection path has been precisely reconstructed in at least one documented case: a user traced their compromise to the "download of a pirated game from a Russian underground forum," according to Help Net Security. The distribution model via pirated software on niche forums represents a structurally difficult vector to counter, because it combines criminal intent with the end user's voluntary behavior that bypasses corporate controls.
Anthropic's Response and Remaining Limits
Anthropic adopted a containment sequence that Dark Reading and SecurityWeek reconstruct convergently: forced sign-out from all active sessions, removal of saved payment methods, refunds for unauthorized charges. The intervention was triggered by detecting anomalies in credit consumption — a pattern suggesting billing monitoring as an indirect compromise signal.
The source does not specify the total financial scope of refunds nor the exact number of users affected. It also remains undocumented whether use of stolen tokens was limited to credit consumption or also involved exfiltration of conversation content. In any case, the malware remains active on compromised systems: removing payment methods does not resolve the primary infection, which requires local device cleanup.
Anthropic explicitly excluded phones and tablets from the alert scope, limiting the phenomenon to desktop clients. This filter suggests the infostealers involved lack mobile equivalents or that the attack surface on Claude services differs across platforms.
August's Patch Apocalypse and the September Outlook
The August 2026 Patch Tuesday cycle set the second-highest volume in history: 398 CVEs addressed, with a breakdown of 42 Critical, 355 Important, and 1 Moderate, according to data reported by Help Net Security. Of this total, Help Net Security found that only one vulnerability was confirmed as actively exploited, with two additional vulnerabilities publicly disclosed before patches were available.
The data underscores a structural discrepancy: growing CVE volume does not translate into a proportional increase in in-the-wild exploits. The challenge for organizations becomes prioritization, not just deployment speed. CVE-2026-62911 on Exchange Server retains a CVSS 8.0 with potential for takeover of all mailboxes; Shadowserver Foundation detected approximately 22,000 unpatched Exchange servers exposed. Microsoft is also working on a fix for CVE-2026-69414 'ShieldBreak' in Microsoft Defender, for which a proof-of-concept exists.
Two cloud vulnerabilities — CVE-2026-65816 and CVE-2026-69555 on Azure Arc, both CVSS 10.0 — have already been mitigated by Microsoft with no user action required, confirming a differentiated patching model between on-premise and cloud.
"The Patch Apocalypse is continuing unabated" — Help Net Security, August 2026 Patch Tuesday analysis
Why the Session Is the New Perimeter
The convergence of the two threads — AI session theft and unstoppable vulnerability growth — draws a scenario where traditional defenses show widening gaps. 2FA, designed to protect the authentication moment, does not cover post-login session persistence. Infostealers have learned to exploit this temporal window, turning consumption-based services like Claude into immediate monetization vaults: prepaid or auto-recharge credits become liquid assets stealable without complex cash-out infrastructure.
A statement from Igor Sahknov, Microsoft CVP Azure Networking, reported by Help Net Security in the Patch Tuesday context, applies a broader reading: "The objective is not to avoid patching. The objective is to create a meaningful layer of defense during the period when patching has not yet been completed." The reasoning shifts focus from total and immediate remediation — unrealistic against hundreds of monthly CVEs — to intermediate network controls that reduce blast radius during the exposure window.
In the Anthropic case, the intermediate control was credit consumption monitoring as a compromise proxy. It's a behavior-based defense logic, not signature-based: it detects anomalies in usage rather than malware on the device. This approach worked, but at the cost of damage already suffered before containment.
What to Do Now
For generative AI service users: verify active sessions in your account, sign out of all sessions after potential exposure, and remove saved payment methods until the device is verified clean. For organizations: integrate billing monitoring as a security signal, not just a finance one, and segment access to consumption-based services with known-device controls. For those managing Exchange infrastructure: prioritize CVE-2026-62911 given the number of exposed servers and the impact of mailbox-wide takeover.
The source does not specify specific remediation measures for infostealer malware on compromised systems. The dossier does not document whether Anthropic provided removal tools or specific antivirus guidance to notified users.
The Question That Remains Open
The Claude incident is not a breach of the service, but reveals how consumption-based LLM business models amplify the economic return of commodity malware. Attackers no longer seek only data to resell: they seek sessions to spend. The transition from credential theft to session theft, now documented with names and mechanisms, demands a revision of the security perimeter to include the token's entire lifecycle, not just its generation.
Simultaneously, the Patch Tuesday record suggests that accelerated vulnerability discovery — partly fueled by AI tools themselves — is creating asymmetric pressure: more flaws disclosed, same human patching capacity. The solution lies not in patch volume, but in the resilience of intermediate layers. Anthropic has shown that billing monitoring can be one such layer. It remains to be seen whether this becomes an industry standard, or remains an ad hoc response to a single incident.
FAQ
Was Anthropic breached?
No. The malware resides on users' devices, not in Anthropic's infrastructure. The company stated this explicitly in its user communication.
Why didn't 2FA protect?
2FA protects the authentication moment, not the subsequent session. Stolen session tokens allow direct access without repeating authentication.
Do refunds cover all losses?
The source does not specify the total refund amount nor whether they were issued to all affected users. Anthropic confirmed refunds for unauthorized charges.
Information verified against cited sources and current as of publication.
Sources
- https://www.helpnetsecurity.com/2026/09/06/week-in-review-claude-accounts-compromised-through-infostealer-patch-tuesday-forecast/
- https://www.darkreading.com/cyberattacks-data-breaches/anthropic-users-infostealer-attacks-session-thefts
- https://www.malwarebytes.com/blog/news/2026/09/infostealers-are-hijacking-claude-accounts-at-users-expense
- https://www.securityweek.com/anthropic-warns-claude-users-of-infostealer-malware-infections/
- https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/
- https://www.helpnetsecurity.com/2026/09/04/september-2026-patch-tuesday-forecast/
- https://www.helpnetsecurity.com/2026/08/31/healthcare-company-mckesson-data-breach/
- https://www.helpnetsecurity.com/2026/09/02/google-scareware-ads-research/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.