AI IndustryAnthropicSep 2, 2026 19:26 UTC

Anthropic's Claude Accounts Targeted in Session Hijacking Attack

Anthropic confirmed that user accounts for its AI assistant 'Claude' were compromised by infosstealer malware and notified affected users around August 30, 2025. Attackers used six types of malware including Vidar and LummaC2 to steal session cookies, bypassing passwords and two-factor authentication to drain account credits. Anthropic implemented forced sign-outs and refunded fraudulent charges.

Anthropic's Claude Accounts Targeted in Session Hijacking Attack

Anthropic confirmed that user accounts for its AI assistant 'Claude' were being fraudulently accessed through malware known as 'infostealers' and sent notification emails to affected users. According to BleepingComputer's August 30 report, attackers stole Claude session cookies from users' computers and used them to drain account credits without logging in with credentials.

A 'session cookie' is a small piece of data that a browser uses to prove that a user has successfully logged in. Typically, when a user logs into a service, the site sends this cookie to the browser, allowing subsequent access without repeatedly entering a password or two-factor authentication code. However, when attackers steal this cookie, they can simply 'paste' it into their own browser to replicate a logged-in state and gain access to the account without needing any password or two-factor authentication. Help Net Security described this technique on August 31 as 'session hijacking becoming the new credential theft.'

Anthropic's notification email identified six types of malicious software: five for Windows—Vidar, LummaC2, StealC, RedLine, and Acreed—and Atomic Stealer for some Mac systems. These are all general-purpose malware designed to copy passwords and cookies stored in browsers, and Claude session information appears to have been collected incidentally. The notification stated: 'Your Claude session was likely one of the targets collected.' Anthropic detected suspicious activity from usage logs, noting that account credits were being replenished and consumed during times when the account owner was not active.

Anthropic's response included forced sign-out of affected accounts, deletion of stored payment methods, and refunds for confirmed fraudulent charges. Forced sign-out was effective because stolen session cookies are tied to specific sessions; ending the session invalidates the cookies. The compromised accounts were personal self-service accounts billed directly via credit card and used separate authentication systems from enterprise Single Sign-On (SSO). This meant enterprise IT administrators could not perform bulk sign-outs, requiring Anthropic to handle the matter directly.

Information about infection vectors is limited. BleepingComputer reported that one affected user on Reddit stated the compromise originated from downloading pirated games. However, infection vectors for other victims have not been disclosed by Anthropic. Additionally, Anthropic has not published the total number of affected accounts or whether enterprise Team and Enterprise plan accounts were included.

This incident demonstrates that enhanced password management and two-factor authentication alone cannot fully prevent session cookie theft. As AI services become more widely adopted, the value of what users can access after logging in—such as conversation histories and permissions for linked applications—continues to increase. The fact that infostealers now target Claude suggests that AI services are becoming increasingly lucrative targets for attackers. For users, the importance of not installing untrusted software is reaffirmed, and for AI service providers, the critical need for real-time detection of abnormal usage patterns is highlighted.

#Anthropic#Claude#Cybersecurity#Malware#SessionHijacking#GenerativeAI#AccountFraud
AI issue Staff

This article is an original work independently written and edited by the AI issue editorial team based on factual reporting. © AI issue. Unauthorized reproduction, redistribution, or use for AI training is prohibited.

Comments

Log in to comment