Anthropic has told a group of Claude subscribers that criminals used ordinary infostealer malware already sitting on their computers to copy active login sessions, then used those stolen sessions to log into the accounts and burn through the usage those subscribers were paying for. The company is signing affected accounts out, stripping saved payment methods and refunding charges it can identify as unauthorized, according to a warning email it has been sending to compromised users since late August 2026. Nothing about the malware is specific to Anthropic’s products; the same infection that steals a Claude session also scoops up banking passwords, work logins and anything else stored in a browser.
The tell that something is wrong, per Anthropic’s own description, is a usage meter that appears to refill and then drain on its own while the account holder is not actively using the service. That pattern reflects how the theft actually works: an attacker is not guessing a password or intercepting a one-time code, but replaying a session that was already authenticated, which means standard login defenses never get a chance to trigger. Anthropic’s outreach has gone out as individual warning emails to specific accounts it flagged as compromised rather than as a blanket notice to its whole subscriber base, so most Claude users have seen no message at all and would have no reason to suspect a problem exists.
Why a stolen cookie beats stolen passwords
Modern accounts are typically protected by a password paired with multi-factor authentication, a combination built to stop someone who only has stolen credentials. Session theft sidesteps both layers at once. Once a person logs in successfully, the site issues the browser a session cookie that keeps them signed in without repeating the password-and-code process on every click, and an infostealer’s job is simply to copy that cookie off the infected machine. An attacker who replays the cookie is treated by the system as the already-logged-in account holder, with no password prompt and no multi-factor challenge standing in the way. Pieter Arntz, a Malware Intelligence Researcher at Malwarebytes, described the technique as a deliberate alternative to guessing passwords or intercepting authentication codes — the attackers go straight for a session that has already cleared both checks.
Five malware families, one shared target
Anthropic has linked the campaign to a specific set of infostealer families: Vidar, LummaC2, StealC, RedLine and Acreed on Windows machines, plus Atomic Stealer, also known as AMOS, on a small number of Mac computers. These are general-purpose credential-stealing tools that criminals have used for years against banking sites and corporate logins; Claude sessions are simply one more item swept up alongside browser passwords and other stored data once a machine is infected. Anthropic has been explicit that the malware has no connection to Claude itself and was not delivered through the product in any way — the infection happens first, through an unrelated download or malicious app, and only afterward does whatever infostealer is running happen to find a live Claude session among the credentials it collects. One Reddit user who received Anthropic’s notice and posted a screenshot of the email publicly traced their own infection to a pirated game they had downloaded, a reminder that the entry point is rarely the AI product itself but whatever software slipped past the victim’s defenses first.
What a hijacked account actually costs
Paid Claude plans can extend beyond a subscription’s built-in session limit through prepaid usage credits, and subscribers who enable auto-reload have the account automatically buy more credits whenever the balance runs low. That billing design is convenient for a legitimate subscriber and expensive in the hands of a thief: once inside, an attacker can exhaust the plan’s included allowance, spend through any prepaid credit balance, and, if auto-reload is switched on, keep triggering fresh purchases on the account holder’s card. Beyond the direct financial cost, a hijacked account hands an attacker a working AI subscription that can be turned toward drafting phishing content, building scam infrastructure or refining malicious code, which is part of why Anthropic frames the sign-outs and card removals as urgent rather than routine account hygiene.
What affected users are being told to do
Anthropic’s email tells recipients it has already removed the card on file and signed out the sessions involved, but is explicit that logging back in safely requires clearing the malware first, since a reinfected browser can simply hand over a fresh session the next time someone signs in. The recommended sequence, echoed in Anthropic’s guidance as reported by BleepingComputer, is to scan and clean the infected computer before doing anything else, then change the password on the email account tied to Claude and turn on multi-factor authentication there, then rotate any other sensitive passwords that were saved in the same browser, including banking and work logins. Only after those steps does Anthropic suggest re-adding a payment method. Anyone who still sees unexplained usage changes or an unrecognized charge after completing that process is directed to contact Anthropic’s user-safety team directly rather than assume the issue has resolved itself.
More from Morning Overview
- Four U.S. startups fired up their first small nuclear reactors, aiming to power AI data centers on-site
- 11 engines built to run well past 200,000 miles
- A handful of car transmissions are so tough that mechanics say they almost never die
- Card skimmers hidden on gas pumps are draining accounts, and there’s a quick way to spot them
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.