Illustrative image generated with AI
Claude Sessions Stolen by Infostealers: How Attackers Bypass Passwords and 2FA
Anthropic warns Claude users of infostealer malware stealing sessions, bypassing passwords and 2FA. Discover attack methods and protection tips.
Text generated by artificial intelligence, published without human review. AI transparency
What happened on August 30
On August 30, 2026, Anthropic began notifying some Claude users that infostealer malware on their PCs had stolen active login sessions. The attackers used those sessions to access accounts and consume usage—credits and limits. The company is logging affected users out of Claude, removing saved payment methods, and refunding charges identified as unauthorized. The exact number of affected users has not been disclosed; on macOS cases are limited to a small number.
In the email sent to compromised users, shared on Reddit, Anthropic explains that a malicious actor is using common infostealers to steal Claude login sessions from victims' computers. One passage clarifies a typical symptom: if usage limits seemed to reset and then drain while the user wasn't using Claude, this was likely the cause. Anthropic's investigation is ongoing, but the company believes the computers were already infected with generic infostealer malware, unrelated to Claude, not installed through Claude or tied to what the user did with the service.
The technique: authenticated session theft
Infostealers copy an already authenticated browser session. This lets the attacker bypass the normal login process with password and two-factor authentication (2FA). There's no need to know credentials or intercept an OTP code: the valid session cookie is reused as is. The malware typically arrives through malicious downloads or applications and steals locally stored information, including browser passwords, login cookies, and credentials from other applications.
The Claude session was likely one of many pieces of data collected, not the primary target. One user who shared the email on Reddit confirmed they had downloaded a pirated game, explaining the system compromise. This case shows how a single malicious executable can harvest all active sessions on a computer at once, including those for AI services, webmail, social media, and work platforms.
Malware identified on Windows and macOS
Anthropic has identified several malware families involved in the operation. On Windows: Vidar, LummaC2, StealC, RedLine, and Acreed. On a small number of Macs: Atomic Stealer, also known as AMOS. All of these are generic infostealers, long present in the cybercriminal landscape and typically distributed through malicious downloads or applications. There is no correlation between the malware and the use of Claude: these are pre-existing infections on victims' computers.
Impact on users: consumed credits and refunds
Affected users experienced unauthorized access to their Claude accounts. The main consequences are consumption of usage limits (credits) and potential unauthorized charges. Anthropic has committed to refunding charges identified as unauthorized. For victims, the first sign was often anomalous behavior in usage limits: they would reset and then drain without the user actually using the service.
The company has also removed saved payment methods from compromised accounts to prevent further unauthorized purchases.
What is still unknown
Some details of the incident have not been made public. The exact number of affected users has not been disclosed. It is not known how long attackers had access to compromised accounts before the notice. It has not been specified whether the contents of Claude conversations were read or exfiltrated. Finally, it is unclear whether the same infostealers also stole credentials or sessions from other services used by victims, although this is likely given the typical behavior of such malware.
What to do if you received the notice
Anthropic warned that logging the user out of Claude stops stolen sessions but does not remove the malware. If the infostealer is still present, the next login session could be stolen the same way. Three actions are recommended.
First: change your Claude credentials and, out of caution, any other service that uses the same password. Second: revoke other active sessions, not only on Claude but also on other services where the infostealer may have copied authentication cookies. Third: remove the malware from the computer with updated antimalware tools. Logging out of Claude alone is not enough; you need to eliminate the infostealer to prevent the new session from being stolen the same way.
It is also worth paying attention to malicious downloads and applications. The pirated game case confirmed on Reddit shows how a single compromised file can trigger session theft. Avoiding pirated software, updating the operating system and browser, and using antimalware with real-time protection reduces the risk of infostealer infections.
Context: valid credentials and defenses that fail
According to The Blue Report 2026, once attackers have valid credentials, only 37% of their actions are blocked. The report measures defenses technique by technique across 338 million simulations run in customer production environments. This data helps explain why authenticated session theft is so effective: traditional controls based on passwords and 2FA do not see the attacker moving with an already valid session.
In this case, access was not attributed to a vulnerability in Claude, but to pre-existing infections by generic malware. Responsibility falls partly on users, but Anthropic's response shows that AI service providers must be prepared to handle accounts compromised by third-party malware. Proactively revoking sessions, removing payment methods, and issuing refunds are containment measures that limit damage, but they do not solve the root problem: malware on the user's device.
Sources
This article is an original reworking based on the sources below.
