Stolen browser sessions let thieves drain paid Claude accounts

Anthropic locks victims out and refunds charges after infostealers hijack active login sessions.

CSBadmin
2 Min Read

Thieves with stolen browser sessions are draining paid Claude usage, prompting Anthropic to lock affected accounts and strip saved cards. The company began signing users out last week after spotting the activity.

Six stealer families are named in the notifications so far: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, with Atomic Stealer seen on a small number of Macs. The stealers quietly copy saved passwords, browser login cookies, and credentials from other local apps, and a bad actor has started picking Claude sessions out of those hauls.

Session theft sidesteps two-factor authentication: the victim logged in once, the site issued a session cookie, and replaying that cookie makes the attacker look like an authenticated user. Anthropic says its systems detected the activity, revoked the affected sessions, removed cards on file, and is refunding unauthorized charges. Usage limits that refilled and then drained while the owner was away are a telltale sign, the company said.

Anthropic stressed that the malware is not related to Claude, was not installed through it, and that phones and tablets do not appear involved. Victims traced infections to unofficial downloads, including one user who cited a pirated game from a Russian forum.

Signing users out stops the stolen sessions, but it does not remove the malware, so the company’s guidance is to scan and clean the machine first, then reset passwords, enable two-factor authentication on the email account, and check card statements. Users should also invalidate active sessions on other services before logging back in.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.