← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Anthropic Claude accounts compromised by infostealer malware replaying session cookies

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Infostealers replayed stolen Claude session cookies into paid accounts.
  • The attack bypassed 2FA and SSO, which provide revocation and visibility, not prevention.
  • Anthropic identified six infostealer families involved, including Vidar and LummaC2.
  • Compromised accounts were self-serve, not governed by corporate identity providers.

Claude Accounts Compromised by Session Cookie Replay

Anthropic informed users that their Claude accounts were compromised by infostealer malware. The attackers used stolen session cookies to access paid accounts, effectively bypassing two-factor authentication (2FA) and single sign-on (SSO) protections. This method allows unauthorized access without needing to interact with the login page.

Mechanism of Attack

Session cookies, which keep users logged in after initial authentication, were copied by general-purpose infostealer malware. By replaying these cookies, attackers appeared to the server as already authenticated users. Anthropic detected the activity through unusual usage patterns, such as limits being refilled and drained while account owners were inactive.

Affected Accounts and Malware Families

The compromised accounts were self-serve, card-billed accounts, which are not managed by corporate identity providers or admin consoles. Anthropic identified six infostealer families involved: Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on macOS. These malware types are known to collect browser login cookies and saved passwords.

Anthropic's Response

Upon discovery, Anthropic notified affected users, signed out the compromised accounts, stripped saved payment methods, and refunded charges incurred by the attackers. While the immediate financial loss from burned usage was small, the primary concern was the potential exposure of data accessible through these unauthorized sessions, none of which were behind enterprise-controlled identities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~30 min · 24 stories · Sep 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Anthropic notified users that infostealer malware compromised their Claude accounts by replaying stolen session cookies, bypassing two-factor authentication and SSO. This incident highlights a vulnerability where session cookies, once stolen, grant access to accounts without needing login credentials, posing a risk to data accessible through these sessions.