Anthropic informed users that their Claude accounts were compromised by infostealer malware. The attackers used stolen session cookies to access paid accounts, effectively bypassing two-factor authentication (2FA) and single sign-on (SSO) protections. This method allows unauthorized access without needing to interact with the login page.
Session cookies, which keep users logged in after initial authentication, were copied by general-purpose infostealer malware. By replaying these cookies, attackers appeared to the server as already authenticated users. Anthropic detected the activity through unusual usage patterns, such as limits being refilled and drained while account owners were inactive.
The compromised accounts were self-serve, card-billed accounts, which are not managed by corporate identity providers or admin consoles. Anthropic identified six infostealer families involved: Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on macOS. These malware types are known to collect browser login cookies and saved passwords.
Upon discovery, Anthropic notified affected users, signed out the compromised accounts, stripped saved payment methods, and refunded charges incurred by the attackers. While the immediate financial loss from burned usage was small, the primary concern was the potential exposure of data accessible through these unauthorized sessions, none of which were behind enterprise-controlled identities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Anthropic notified users that infostealer malware compromised their Claude accounts by replaying stolen session cookies, bypassing two-factor authentication and SSO. This incident highlights a vulnerability where session cookies, once stolen, grant access to accounts without needing login credentials, posing a risk to data accessible through these sessions.