Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Anthropic has emailed affected users warning that infostealer malware on their computers stole active Claude sessions. Attackers use those sessions to access accounts and burn through usage limits, generating charges that Anthropic is now refunding. The incident confirms that authenticated sessions for generative AI services have become a target with immediate monetary value for the underground economy.
- Anthropic identified five malware families on Windows (Vidar, LummaC2, StealC, RedLine, Acreed) and Atomic Stealer (AMOS) on a small number of Macs.
- Attackers use stolen sessions to access accounts without re-entering passwords or 2FA, consuming usage limits at the expense of legitimate users.
- Anthropic is revoking compromised sessions, removing saved payment methods, and refunding charges it identifies as unauthorized.
- The source does not specify the exact number of affected users nor the start date of the attack campaign.
How the Attack Chain Works
Infostealer malware does not attack Anthropic's systems directly. It compromises Windows and Mac endpoints, extracts authenticated browser cookies and sessions from infected devices, then resells or uses them directly. When a Claude session falls into a threat actor's hands, they can access the account without going through the normal authentication flow.
Anthropic clarified in its email that the malware is unrelated to Claude, was not installed via Claude, and that Claude sessions were merely one of many data types collected. According to the source, the company wrote: "Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them." This indicates a phase of selective post-compromise monetization, not a targeted attack on the platform from the outset.
Why 2FA Does Not Stop This Attack
The technical mechanism of session theft operates below the authentication layer. When a user completes login and 2FA, the browser obtains a session token that keeps access active. Infostealers copy that token exactly where it resides: in browser memory or local storage files. The attacker transfers it to their own system and reuses the already-authenticated session.
The source explicitly states that infostealers "can copy an already authenticated browser session, which means the attacker may not need to go through the normal password and 2FA login process again." 2FA has not been bypassed; it simply is not prompted because the session is already valid. This distinction is technical but decisive for understanding the limits of post-authentication controls.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage"
Anthropic's Response and Its Limits
Anthropic is acting on three fronts: revoking compromised sessions, removing saved payment methods, and refunding unauthorized charges. The company email warns, however, that "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware." Endpoint disinfection remains the user's responsibility.
Anthropic writes that it is refunding "charges it identifies as unauthorized," leaving the identification criteria unspecified. No public security advisory nor indicators of compromise shared by the company beyond the direct emails have emerged.
What to Do Now
Users who received Anthropic's email must act on two levels: immediate containment and endpoint remediation. On the immediate front, Anthropic has already revoked compromised sessions and removed saved payment methods. Users should verify that no unauthorized charges appear and await refunds for expenses Anthropic identifies as such.
On the endpoint front, signing out of Claude does not remove the malware. Users must run a full system scan with updated security tools, considering that the six identified malware families (five on Windows, one on Mac) operate with established session-theft techniques. After cleanup, it is necessary to change Claude credentials and revoke any other active sessions on other devices.
For enterprise teams distributing Claude access, the case suggests monitoring usage limits more frequently. An anomalous consumption pattern — limits that "refill and drain" while the user is inactive, as Anthropic describes — is an indicator of a compromised session.
The Market for AI Sessions as a New Perimeter
The incident signals an evolution in the credential-theft economy: authenticated sessions for consumption-based services become tradable goods with immediate economic value. Unlike banking credentials, which require complex cash-out infrastructure, a Claude session monetizes directly by consuming APIs and prepaid credits. Operators can choose to use the session themselves or resell it to buyers who do not even possess the malware.
For companies distributing Claude access to teams, this turns browser sessions into assets that must be monitored. Traditional post-authentication controls are not designed to detect a cloned session: the token is valid, the device is unknown but not suspicious by definition. The source does not document whether Anthropic is addressing this architectural gap.
Frequently Asked Questions
Was Anthropic breached?
No. The attack involves user endpoints compromised by infostealer malware, not Anthropic's systems. The company explicitly stated the malware is unrelated to Claude and was not installed via Claude.
Why didn't 2FA protect me?
2FA protects the moment of login. The malware steals the already-authenticated session, bypassing that moment entirely. It is an attack on the session token, not the authentication mechanism.
What happens if I sign out of Claude on my device?
Anthropic revokes compromised sessions as part of its response. Signing out stops the abusive use of that specific session, but does not remove the malware from the endpoint.
Sources
Information is based on the cited source and current as of publication.
Sources
- https://www.bleepingcomputer.com/
- https://www.bleepingcomputer.com/tutorials/
- https://www.bleepingcomputer.com/download/
- https://deals.bleepingcomputer.com/
- https://www.bleepingcomputer.com/vpn/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.