Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.
The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” Anthropic said in an email sent to an affected user, who shared it on Reddit.
“If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause,” Anthropic warned.
Anthropic sending emails to affected users
Source: Reddit
It is also worth noting that infostealers can copy an already authenticated browser session, which means the attacker may not need to go through the normal password and 2FA login process again.
Anthropic links attacks to Vidar, LummaC2, StealC, RedLine and other infostealers
In the email, which is also being sent out to other compromised account holders, Anthropic says its investigation is ongoing, but computers were likely already infected with general-purpose infostealer malware.
Advertisement
“We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,” the company stressed.
According to Anthropic, the malware typically arrives through downloads or malicious apps and steals information stored locally, including browser passwords, login cookies, and credentials belonging to other apps.
“Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them,” Anthropic said.
In this case, the Redditor who shared the email confirmed that they downloaded a pirated game, which explains why their system got compromised.
Advertisement
Anthropic has identified multiple malware, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of Macs.
If you get affected, Claude will revoke compromised sessions and remove saved payment methods to prevent unauthorized purchases.
“Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware,” Anthropic warned. “If it’s still on your computer, your next login session could be stolen the same way.”
Anthropic has urged affected users to take basic security steps, including changing credentials, revoking other sessions, and removing the malware from the PCs.
Advertisement
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
You must be logged in to post a comment Login