FR
live

Infostealers drain Claude sessions without a password, and Anthropic signs compromised accounts out

On August 30, 2026, Anthropic warned users that infostealers had stolen their active Claude sessions to consume their usage. A stolen session cookie bypasses both password and 2FA — and paid AI accounts are becoming a monetization target in their own right.

A neat row of identical padlocks on a dark rack, one padlock hanging open with its shackle catching amber light.

August 30, 2026. Anthropic warned some Claude users that infostealers on their machines had stolen their active sessions, letting an attacker access the account and consume its usage. August 31, 2026. The case was covered by BleepingComputer and confirmed by email screenshots shared on Reddit. The lesson goes well beyond Claude: a stolen session cookie bypasses both password and 2FA, and paid AI subscriptions have become a monetization target of their own.

What is striking about this incident is not the sophistication — it is the banality. Infostealers are opportunistic malware that vacuum up locally stored data: browser passwords, session cookies, credentials for other apps. Anthropic says it plainly: “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude.” The Claude session was just one more line in the collected loot — one that an actor eventually got around to using.

To understand why this works, look at what an infostealer copies. When a user logs into a service, the server issues a session cookie that proves they are already authenticated. That cookie, stored in the browser, is a master key: presenting it is equivalent to proving you are logged in, without going through the password again.

The catch is that the password and 2FA only protect the creation of a session, not its later use. An infostealer that copies an already-issued session cookie does not need the password, nor the second factor. It simply “replays” the session. That is exactly what Anthropic describes: the attacker uses “those login sessions to access Claude accounts and consume their usage”, without ever logging in again.

For victims, the symptom is subtle and treacherous. Anthropic puts it in its email: “If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.” In other words, the theft does not show up in your passwords — it shows up on your bill.

The malware families identified

Anthropic tied the campaign to several known infostealers. On Windows: Vidar, LummaC2, StealC, RedLine, and Acreed. On macOS, a small number of machines carried Atomic Stealer (AMOS). These are names that have circulated in cybercrime forums for years, often sold as malware-as-a-service — the buyer needs no skill to deploy the collection.

The infection vector, meanwhile, remains the same as ever: shady downloads and malicious apps. The case shared on Reddit is exemplary — the user admits downloading a pirated game, which compromised the machine. The malware then harvested the Claude session along with everything else, and an actor used it to drain the account’s credit.

Anthropic’s response, and its limits

Anthropic’s reaction is correct, within the limits of what a provider can do. The company signs out compromised accounts, removes saved payment methods, and refunds charges it identifies as unauthorized. On the user side, it recommends changing credentials, revoking other sessions, and — above all — removing the malware.

But Anthropic states the limit itself, in a sentence worth quoting in full: “Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware. If it’s still on your computer, your next login session could be stolen the same way.” In plain terms, the provider can put out the fire on the account side; it cannot clean the machine that is still burning. The cleanup remains the user’s job — and it is precisely the link most people skip.

What this reveals about the infostealer market

The Claude episode marks a shift in how infostealers are monetized. Historically, stolen session loot mostly served to empty bank accounts, drain crypto wallets, or resell credentials in bulk. Now a Claude subscription — and more broadly any paid AI account with usage credit — is itself a cashable asset. An active Claude account grants compute capacity and quotas an attacker can consume directly, resell, or use to run their own tasks at the victim’s expense.

The structural consequence is clear: as professional AI usage becomes monetized, AI identities become assets to steal, on par with a bank account. For a CISO, that means one thing: the company’s AI accounts — Claude, ChatGPT, Gemini, and tomorrow every agent — must be treated as privileged accounts, not as harmless tools.

A theft economy that is going pro

The Claude case fits a value chain that is already well-oiled. Infostealers sell as malware-as-a-service — a few dozen dollars a month for a control panel, a builder, and support. The collected logs (credentials, cookies, wallets) then resell in bulk on specialized markets. A Claude or ChatGPT session cookie is one asset among many, but an increasingly prized one: it grants compute capacity billed to the victim’s account.

The mechanics are all the more insidious because they are silent. Unlike a bank card, which a bank blocks on an abnormal transaction, an AI account can be drained slowly, below detection thresholds, until the quota runs out. Victims often discover the theft only by watching their usage limits empty for no reason — or, worst case, on the bill.

A useful distinction for technical teams: this is not API-key theft. A leaked API key is a bearer token you can rotate and revoke; a stolen session cookie is a live, already-authenticated session that often survives a password change until the provider or the user invalidates it. That is why Anthropic’s response — force-sign-out plus removing payment methods — is the correct move, and why users who only change their password are still exposed. The control you actually need is session revocation, and it is the part most people skip.

For defense, four steps, in order:

  • Clean first: remove the malware, otherwise every new session will be stolen again.
  • Revoke next: sign out of all devices and invalidate active sessions.
  • Rotate secrets: passwords, and above all any API keys that may have passed through.
  • Harden access: MFA, short sessions, and no persistent cookies on unmanaged devices.

One more point worth underlining for organizations: this is unlikely to stay Claude-specific. Every paid AI service that keeps long-lived browser sessions — ChatGPT, Gemini, Copilot, and the growing class of agent tools — presents the same target, and infostealer operators adapt to wherever stored value migrates. The mitigation is equally uniform: treat the AI login as a privileged credential, and assume any device that handles those sessions can become a source of theft. For defenders, the blunt message is that the perimeter has moved — from the password prompt to the session store.

Verdict

If you are an individual user, do not stop at changing your password: remove the malware first, then change credentials and revoke all active sessions. A fresh password on a still-infected machine will be stolen at the next login.

If you manage AI access for a company, enforce SSO, mandatory MFA, short session lifetimes, and ban persistent cookies on unmanaged devices. And assume that infostealer logs — already resold by the millions — will increasingly target paid AI usage, not just bank accounts.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

← Back to the feed

Type at least two characters.

navigate open esc dismiss