Infostealers drain Claude sessions without a password, and Anthropic signs compromised accounts out
On August 30, 2026, Anthropic warned users that infostealers had stolen their active Claude sessions to consume their usage. A stolen session cookie bypasses both password and 2FA — and paid AI accounts are becoming a monetization target in their own right.