← Latest briefing

Technology

Anthropic signs out Claude users and removes saved cards following infostealer attacks

Threat actors used session cookies stolen directly from customer devices to bypass authentication, consume usage limits, and accrue unauthorized fees.

The short version

  • Anthropic terminated active sessions, removed saved payment methods, and refunded unauthorized fees for affected Claude users.
  • The incident originated from general infostealer malware on users' own computers, not a direct security breach of Anthropic's systems.
  • Stolen browser session cookies enabled attackers to bypass passwords and two-factor authentication to access AI accounts.
  • Users must clean the malware from their machines and secure associated emails before safely re-adding payment methods.

Key facts

  • Anthropic notified affected users that it logged them out, deleted their saved payment cards, and refunded unauthorized usage fees caused by hijacked sessions.[Engadget]
  • The company stated that the issue stemmed from infostealer malware on users' personal devices rather than a security compromise of Anthropic's infrastructure.[Engadget]
  • Anthropic identified six malware strains behind the activity: Vidar, Lumma, StealC, RedLine, and Acreed on Windows, alongside Atomic Stealer on macOS devices.[Engadget]
  • Attackers used stolen active session cookies to enter accounts already authenticated, circumventing standard password and two-factor authentication prompts.[Engadget]
  • Cybersecurity researchers have reported that stolen AI service credentials are frequently resold or pooled into proxy services that offer discounted access to platforms like Claude, ChatGPT, and Gemini.[Engadget]

What remains uncertain

  • The total number of impacted Claude users and the full financial sum of unauthorized charges have not been publicly disclosed.[Engadget]

Sources