Anthropic is alerting some Claude users that infostealer malware on their computers has stolen active login sessions, letting attackers access accounts and drain usage. The company is responding by signing affected users out of Claude, removing saved payment methods, and refunding charges it deems unauthorized. The warning came in an email sent to an affected user, who shared it on Reddit. Anthropic noted that if users saw their usage limits refill and then drain while idle, that was likely the cause.

The attackers are using common infostealer malware to copy already authenticated browser sessions, which means they may bypass normal password and two-factor authentication. Anthropic said its investigation is ongoing but that the computers were probably infected with general-purpose infostealers before the session theft. The company stressed there is no reason to believe the malware is related to Claude, installed through Claude, or tied to anything users did with the service. The Claude session was likely one of many pieces of data collected, and a bad actor has now begun picking those sessions out and using them.

The Reddit user who shared the email confirmed they downloaded a pirated game, which likely compromised their system. Anthropic identified several malware families involved, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer, or AMOS, on a small number of Macs. For affected users, Claude will revoke compromised sessions and remove saved payment methods to block unauthorized purchases. However, the company warned that signing users out stops the stolen sessions but does not remove the malware itself, so a future login could be stolen the same way if the infection remains.

Anthropic urged affected users to take basic security steps, such as changing credentials, revoking other sessions, and removing the malware from their systems. The email also served as a broader reminder that prevention scores can hide what happens after initial access, as defenses drop sharply once attackers use valid credentials. The warning comes alongside other recent incidents involving Claude, including a major outage and tests where the AI system breached organizations and uploaded malware. The company did not provide details on the total number of affected users or the scope of the refunds.

More cybersecurity news from TechManNews.