Home/anthropic/Anthropic forces automatic sign‑outs of Claude accounts after malware steals session data
A watercolour illustration of a stylized computer monitor displaying the Claude logo with a cracked padlock overlay, while a shadowy, abstract malware silhouette looms over the screen; the background hints at binary code drifting like mist. No text, no logos.
AnthropicPublished 4 September 20263 min read

Anthropic forces automatic sign‑outs of Claude accounts after malware steals session data

Automatic Sign‑Out Response

Anthropic has begun automatically signing out Claude users, deleting stored payment cards and refunding unauthorized charges after a wave of credential theft.

The company disclosed the measure in an email sent to affected customers last week, which later appeared on Reddit.

According to SecurityWeek, Anthropic traced the abuse to infostealer malware that harvested active Claude login sessions from users' computers rather than a breach of its own systems.

The stolen sessions allowed attackers to consume usage limits and incur charges without the victims' knowledge.

The email warned, "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," the email reads.

In response, Anthropic forced sign‑outs of the compromised sessions, removed the card on file and issued refunds for any extra usage tied to the activity.

The company clarified that signing users out does not eliminate the underlying malware, which must be removed separately.

Both Windows and macOS platforms are reported to be affected by the campaign.

Malware Families Behind the Hijacks

Anthropic has identified six malware families responsible so far: Vidar, Lumma, StealC, RedLine, Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs.

None of these infostealers were built specifically to target Claude; they are general‑purpose stealers that typically accompany malicious downloads.

Once installed, the malware extracts saved passwords and browser cookies, enabling threat actors to hijack accounts by replaying authentication tokens.

In this case, the stolen cookies contained Claude session tokens that keep a user logged in across page loads, bypassing password and two‑factor prompts.

An attacker who replays a stolen cookie can assume the victim’s authenticated session and issue prompts that consume compute resources.

An attacker who replays a stolen cookie can assume the victim’s authenticated session and issue prompts that consume compute resources.

Implications for AI Account Security

Anthropic recommends users first eradicate the malware, then reset their email password and enable two‑factor authentication before adding payment details again.

The value of a hijacked Claude account stems from its resale potential; CrowdStrike’s Adam Meyers told Axios that a market exists for stolen credentials to Claude, ChatGPT and Gemini.

Palo Alto Networks’ Unit 42 linked compromised accounts to proxy services known as transfer stations, which pool stolen credentials and sell AI access at a discount.

While Anthropic does not disclose exact Claude usage limits, each prompt incurs a compute cost that the company absorbs when a stolen session runs.

An attacker with a saved payment method can also purchase additional usage on the victim’s account, prompting Anthropic to delete payment information as a preventive step.

In May, Anthropic doubled Claude Code rate limits for paid users because demand outpaced capacity, illustrating the high consumption potential of compromised accounts.

Although Anthropic can invalidate known stolen sessions and reimburse fraudulent charges, the malware on a user’s machine can generate fresh cookies for future hijacks.

Users are therefore urged to clean their devices before re‑logging to Claude to prevent a repeat of the theft.

Anthropic has not responded to requests for comment at the time of publication.

Why This Matters: The incident shows that AI service credentials are now a lucrative target, and protecting session cookies is essential to avoid unauthorized usage and financial loss.

#anthropic#ai#digest#auto

This digest was compiled from:

Share this digest

Share on XWhatsAppLinkedInTelegram

People Also Ask

Share your thoughts

Reactions, corrections, or insights — all welcome.

0/2000