AI leader Anthropic has detected a campaign where infostealer malware allowed attackers to hijack user sessions. To protect customers, the company has revoked payment data and forced logouts for affected accounts.

  • Infostealer malware (Vidar, Lumma, etc.) hijacked active Claude AI login sessions.
  • Anthropic proactively removed saved payment methods and refunded unauthorized charges.
  • The breach occurred via compromised user devices, not a flaw in Claude's internal infrastructure.

Anthropic, the AI powerhouse behind Claude, has issued a critical security warning to its user base. The company revealed that a wave of infostealer malware targeting personal computers has enabled cybercriminals to hijack active login sessions, allowing them to exploit account usage limits and access private data.

According to an email sent to affected customers, the malware identified includes Vidar, Lumma, StealC, RedLine, and Acreed for Windows users, as well as Atomic Stealer (AMOS) affecting a smaller number of macOS devices. These malicious programs typically enter a system through unofficial software downloads or deceptive applications.

The mechanism of the attack is subtle: the malware silently scrapes saved passwords, browser login cookies, and credentials from local applications. Once these 'session cookies' are stolen, attackers can bypass traditional login screens and enter the account as if they were the legitimate user.

Why This Matters

BozokMedia analysis shows that this incident highlights a critical vulnerability in the modern web ecosystem: Session Hijacking. As AI agents become more integrated into business workflows, the theft of a session cookie is as dangerous as stealing a password. This underscores a shift in the threat landscape where the 'endpoint'—the user's own laptop—is the primary gateway for high-level corporate espionage and account fraud.

"Session cookies are the keys to the kingdom; once stolen, they render most traditional authentication methods obsolete."

In a decisive response, Anthropic immediately signed out all compromised sessions and took the drastic step of removing saved payment methods to prevent further financial loss. The company has also confirmed that any charges identified as unauthorized have been refunded.

Users have been explicitly cautioned not to re-add their payment information until they have performed a comprehensive system scan and ensured that all traces of malware have been eradicated from their hardware.

Malware Strain Target OS Primary Function
Vidar, Lumma, RedLine Windows Credential & Cookie Harvesting
Atomic Stealer (AMOS) macOS System-wide Data Theft
Did You Know?: Infostealer malware is often bundled with 'cracked' software or fake game mods, making it a common threat for users seeking free versions of paid software.

Frequently Asked Questions

Q1: Was Anthropic's central database breached?
No. The company clarified that the malware resided on the users' local computers, not on Anthropic's servers.

Q2: How can I tell if my account was affected?
Users who noticed their usage limits draining without active use were the primary targets of this specific campaign.