The Login Was Real, The Session Was Stolen

Anthropic has begun notifying an unspecified number of Claude users that infostealer malware on their own computers copied their active, already-authenticated Claude session cookies, letting attackers use their accounts without ever seeing a password or a two-factor code.

Infostealers do not guess or phish credentials. They grab what is already stored locally in a browser. As Anthropic put it: 'It's general-purpose malware that typically arrives with an unofficial download or a malicious app, and it quietly copies saved passwords, login cookies in browsers, and credentials for other apps running locally.' A stolen session cookie lets an attacker replay an already logged-in session, sidestepping password and multi-factor checks entirely.

How Anthropic Noticed

The telltale sign was not a security alert but a billing pattern: accounts whose usage limits appeared to refill and then drain while the legitimate owner was not using Claude. Anthropic's own description: 'If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause.'

The campaign traces to five malware families on Windows, Vidar, LummaC2, StealC, RedLine and Acreed, and one on Mac, Atomic Stealer (AMOS), affecting a small number of systems. In at least one case reported alongside the disclosure, the infection began with a pirated game downloaded from a Russian forum, a reminder that the entry point had nothing to do with Claude itself.

What Anthropic Did, and Could Not Do

Anthropic's response was to revoke the stolen sessions, sign affected users out, remove saved payment methods, and refund charges it identified as unauthorized.

The company was direct about the limit of that fix: 'Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware.' A freshly issued session on the same infected machine can be stolen again the next time the user logs in. The account-side response buys time. It does not solve the underlying infection.

The Blind Spot For Any Company Running AI Seats

Most organizations still treat an AI subscription like ordinary SaaS: protect it with a strong password and multi-factor authentication, rotate credentials on a schedule, and consider the job done. Session-cookie theft defeats both controls at once, because it never touches the login page at all.

The fraud signal here was not a suspicious transaction. It was a usage quota draining on its own, a metric most security dashboards were never built to watch. Any organization issuing Claude, or a comparable AI tool, to staff needs a device-hygiene policy and a usage-anomaly alert of its own, because a vendor can revoke a session after the fact but cannot inoculate an employee's laptop against the next infostealer download.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.