AI

Security

BleepingComputer

Anthropic Warns Claude Users: Malware Is Hijacking Accounts to Drain Subscriptions

Summary

Anthropic is emailing Claude subscribers whose accounts were compromised by infostealer malware, a category of malicious software that copies session cookies from your browser rather than stealing your password. Because the attack uses an already-authenticated session, it bypasses two-factor authentication entirely. Attackers are using the stolen sessions to burn through Claude usage limits and, in some cases, make unauthorized charges. Anthropic is signing out affected accounts, removing saved payment methods, and refunding charges it identifies as unauthorized. On Windows, the malware families involved include Vidar, LummaC2, StealC, and RedLine. On Mac, Atomic Stealer was found in fewer cases. Most infections were caused by downloading pirated software.

Why it matters

Anthropic’s systems were not breached. This is general-purpose malware that happens to target Claude sessions among hundreds of other stored credentials. But the session-cookie vector is effective precisely because it makes password changes and 2FA useless after the fact. Anyone whose Claude usage spiked and then dropped during inactive periods should treat their machine as potentially compromised and run a malware scan before logging back in.

HTD Says

Anthropic is warning Claude users that their accounts are being hijacked by malware that steals browser session cookies, bypasses two-factor authentication entirely, and burns through their subscription limits before they notice. The fix starts on their PC, not in their Claude account. Malware is not anything new. It’s just extending its reach to other vulnerable areas.

The biggest takeaway here is that it is not a hole in Anthropic’s design. In some ways, Anthropic is yet another victim, along with the consumers it impacts. And everything circles back to end-user security awareness and readiness. The biggest piece of advice from me, a nagging dad: don’t click on links you don’t know, don’t download questionable software, and review your usage (AI or otherwise) during hours when you are actually not working.

Because this session stealing happens behind the authentication wall, it’s a bit scarier. And it affects Windows and Mac users (though Macs are less affected).

Uh-oh! It looks like you're using an ad blocker.

HighTechDad.com relies on ads to provide free content and sustain my operations. By turning off your ad blocker for HighTechDad, you help support me and ensure I can continue offering valuable content without any cost to you.

I truly appreciate your understanding and support. Thank you for considering disabling your ad blocker for this website!

Cheers, Michael ("HighTechDad")