Anthropic forces automatic sign‑outs of Claude accounts after malware steals session data
Automatic Sign‑Out Response
Anthropic has begun automatically signing out Claude users, deleting stored payment cards and refunding unauthorized charges after a wave of credential theft.
The company disclosed the measure in an email sent to affected customers last week, which later appeared on Reddit.
According to SecurityWeek, Anthropic traced the abuse to infostealer malware that harvested active Claude login sessions from users' computers rather than a breach of its own systems.
The stolen sessions allowed attackers to consume usage limits and incur charges without the victims' knowledge.
The email warned, "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," the email reads.
In response, Anthropic forced sign‑outs of the compromised sessions, removed the card on file and issued refunds for any extra usage tied to the activity.
The company clarified that signing users out does not eliminate the underlying malware, which must be removed separately.
Both Windows and macOS platforms are reported to be affected by the campaign.
Malware Families Behind the Hijacks
Anthropic has identified six malware families responsible so far: Vidar, Lumma, StealC, RedLine, Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs.
None of these infostealers were built specifically to target Claude; they are general‑purpose stealers that typically accompany malicious downloads.
Once installed, the malware extracts saved passwords and browser cookies, enabling threat actors to hijack accounts by replaying authentication tokens.
In this case, the stolen cookies contained Claude session tokens that keep a user logged in across page loads, bypassing password and two‑factor prompts.
An attacker who replays a stolen cookie can assume the victim’s authenticated session and issue prompts that consume compute resources.
An attacker who replays a stolen cookie can assume the victim’s authenticated session and issue prompts that consume compute resources.
Implications for AI Account Security
Anthropic recommends users first eradicate the malware, then reset their email password and enable two‑factor authentication before adding payment details again.
The value of a hijacked Claude account stems from its resale potential; CrowdStrike’s Adam Meyers told Axios that a market exists for stolen credentials to Claude, ChatGPT and Gemini.
Palo Alto Networks’ Unit 42 linked compromised accounts to proxy services known as transfer stations, which pool stolen credentials and sell AI access at a discount.
While Anthropic does not disclose exact Claude usage limits, each prompt incurs a compute cost that the company absorbs when a stolen session runs.
An attacker with a saved payment method can also purchase additional usage on the victim’s account, prompting Anthropic to delete payment information as a preventive step.
In May, Anthropic doubled Claude Code rate limits for paid users because demand outpaced capacity, illustrating the high consumption potential of compromised accounts.
Although Anthropic can invalidate known stolen sessions and reimburse fraudulent charges, the malware on a user’s machine can generate fresh cookies for future hijacks.
Users are therefore urged to clean their devices before re‑logging to Claude to prevent a repeat of the theft.
Anthropic has not responded to requests for comment at the time of publication.
Why This Matters: The incident shows that AI service credentials are now a lucrative target, and protecting session cookies is essential to avoid unauthorized usage and financial loss.
This digest was compiled from:
Share this digest
People Also Ask
- Anthropic’s Upcoming IPO: Timeline and Unusual Deal Structure Revealed
Anthropic is set to launch an IPO in September‑October with a unique structure that may allow existing shareholders to sell and impose longer lockup periods.
- Anthropic Unveils Claude Fable 5.1 and Mythos 5.1, Detailing Their Features
Anthropic releases Claude Fable 5.1 for everyone and a restricted Claude Mythos 5.1 for vetted cyber and life‑science firms, highlighting cost cuts and stronger benchmarks.
- Anthropic Regains Favor with Trump Administration After Pentagon Dispute, Says Commerce Secretary
Pentagon Block and Legal Victory Defense Secretary Pete Hegseth barred Anthropic from certain military contracts becaus...
Share your thoughts
Reactions, corrections, or insights — all welcome.
