2 Sources
[1]
Anthropic cracks down on hijacked user accounts mining AI tokens
Rather than paying for their own Claude usage, crims are using malware to steal access to other people's accounts. Aware of this issue, Anthropic has signed at least one affected user out and removed the saved payment method to stop stolen sessions being abused. According to an email shared by Reddit user WorriedAssociate7029, who sent a copy to The Register, Anthropic has been keeping an eye on a threat actor using infostealer malware to hijack Claude login details, session cookies, and other info needed to subvert multifactor authentication on user accounts. Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves. Fortunately for WorriedAssociate7029, Anthropic logged the user out of their account and deleted their stored payment method because it had detected evidence of attempted fraud. "A few days ago, my social media accounts were hacked," WorriedAssociate said, adding that they'd managed to track the malware down with the help of Claude Opus 5 Max and, they believe, cleaned the system. "But last night I received this email from Anthropic warning me of an attempt to steal tokens via the API." They explained that the attempt failed, apparently thanks to Anthropic spotting it, but they realized that meant that the cybercriminal behind the incident seemed to have hijacked Google account credentials, cookies, and session IDs as well, since that's how they were signed into Claude. After changing their password again and removing all active sessions, it appears they are now safe. Who's eating your cookies? Anthropic made clear in the email that the credential theft wave it's identified has nothing to do with Claude itself, nor is it some sort of fancy, new-fangled, agentic AI malware that's being used to create a base of accounts for bad actors to abuse. This is just good old-fashioned infostealer malware being turned to a new purpose, the email explains. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the email forwarded to us by WorriedAssociate and posted to Reddit stated. "Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them." In this case, it's well-known infostealing malware too: Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer have all been fingered by Anthropic as being used to steal Claude credentials, sessions, and cookies. As for WorriedAssociate, they copped to making a noob mistake that led to their infection. "I got fooled like a rookie by downloading a cracked game," they admitted in a comment on their post. "Never again." As in their post, WorriedAssociate told us in a chat that they gave credit to Anthropic for cluing them in to the fact that they hadn't fully secured their accounts, and said they appreciated what the company did to help lock their Claude account down. "There have been several cases on Reddit in the past of accounts being hacked to steal tokens, and Anthropic's customer service seems pretty dreadful when it comes to refunds and account recovery," they told us. "This email appears to be new, and measures have finally been put in place to protect AI users." "Tokens are valuable and can be resold," WorriedAssociate added. So let this be a lesson: Providers might not catch every case of account theft, and AI accounts are the new hotness. Don't let your tokens be burned by someone else - they're expensive and the last thing you want them to be used for is someone else's work. ®
[2]
Hackers Target Claude Accounts With Malware That Steals Login Sessions | PYMNTS.com
Cyber Security News reported Monday (Aug. 31) that several information-stealing malware families, including Vidar, Lumma, StealC, RedLine and Acreed on Windows and Atomic Stealer on macOS, have been used to collect browser cookies, saved passwords and other credentials from infected devices. The threat is particularly significant because stolen session cookies can allow attackers to impersonate an already-authenticated user. Anthropic identified cases in which attackers appeared to consume paid Claude usage after account owners had stopped using the service. Because the attackers can reuse an existing session, traditional login protections such as multifactor authentication may not prevent the takeover. A separate campaign tracked by cybersecurity firm Huntress used Claude's own infrastructure to distribute malware, according to Cyber Security News. Between July 21 and July 22, attackers reportedly used sponsored Bing advertisements to direct users searching for the Claude desktop application to a malicious Claude Artifact hosted on the legitimate claude.ai domain. The fake installer deployed SectopRAT, a remote-access Trojan capable of harvesting browser credentials, cookies, files and payment-card information, the report said. Huntress identified at least 29 compromised organizations and roughly 7,100 downloads before Anthropic removed the malicious page. The activity also highlights a broader security concern for businesses adopting AI tools. Cyber Security News reported that attackers have begun hiding malicious instructions in files used by Claude's agent, potentially allowing malware to be downloaded again when compromised files are reintroduced. Anthropic has responded by signing affected accounts out, removing stored payment methods and refunding confirmed fraudulent charges, according to Cyber Security News. The company has warned that those measures do not remove malware from infected devices. The security concerns extend beyond stolen credentials. In July, Alibaba barred employees from using Anthropic's AI tools at work and placed Claude Code on a high-risk software list, following Anthropic's allegations that Alibaba had conducted a large-scale effort to extract capabilities from its models.
Share
Copy Link
Cybercriminals are using infostealer malware like Vidar, Lumma, and StealC to hijack Claude accounts and steal AI tokens without paying. Anthropic has responded by signing out affected users, removing stored payment methods, and refunding fraudulent charges. The attacks exploit session cookies to bypass multifactor authentication.
Anthropichas identified a wave of account hijacking targeting Claude accounts, where cybercriminals use infostealer malware to steal login credentials and consume premium AI services without paying. Rather than targeting Anthropic's infrastructure directly, attackers are deploying well-known infostealer malware including Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on macOS to collect browser cookies, saved passwords, and session cookies from infected devices
1
2
. The threat actor then uses this stolen information to access hijacked user accounts and rack up charges for premium Claude usage on someone else's dime.
Source: PYMNTS
The malware steals login credentials and session data that allows attackers to bypass traditional security measures. Because stolen session cookies enable attackers to impersonate already-authenticated users, even multifactor authentication cannot prevent these account takeovers. Anthropic has detected cases where attackers consumed paid Claude usage after legitimate account owners had stopped using the service, making the fraud harder to detect initially
2
.The attack chain begins when users unknowingly install infostealer malware on their devices. One Reddit user, WorriedAssociate7029, admitted to downloading a cracked game that infected their system. The malware collected credentials from multiple accounts, including social media and Google account credentials, along with cookies and session IDs
1
. Days later, Anthropic detected the attempted fraud and sent a warning email explaining that a bad actor had started picking Claude sessions out of the collected data and using them to steal AI tokens through the API.Anthropicmade clear in communications to affected users that the credential theft has nothing to do with Claude itself. The company emphasized that this is traditional infostealer malware being repurposed for a new target: valuable AI tokens that can be resold on underground markets
1
. As AI services become more expensive and widely adopted, cybercriminals have identified AI tokens as a lucrative commodity worth stealing.Upon detecting suspicious activity, Anthropic has taken proactive measures to protect affected accounts. The company has been signing users out of their accounts and removing stored payment methods to prevent further fraudulent charges. In the case shared by WorriedAssociate7029, Anthropic successfully blocked the attempted fraud before significant damage occurred
1
.Anthropichas also committed to refunding confirmed fraudulent charges for victims of these attacks. However, the company has warned users that while it can secure Claude accounts, these protective measures do not remove malware from infected devices
2
. Users must take additional steps to clean their systems and secure all compromised accounts, not just Claude.Related Stories
A separate campaign tracked by cybersecurity firm Huntress revealed another attack vector exploiting Claude's infrastructure. Between July 21 and July 22, attackers used sponsored Bing advertisements to direct users searching for the Claude desktop application to a malicious Claude Artifact hosted on the legitimate claude.ai domain. This fake installer deployed SectopRAT, a remote-access Trojan capable of harvesting browser credentials, cookies, files, and payment-card information. Huntress identified at least 29 compromised organizations and roughly 7,100 downloads before Anthropic removed the malicious page
2
.The activity highlights growing cybersecurity concerns for businesses adopting AI tools. Attackers have begun hiding malicious instructions in files used by Claude's agent, potentially allowing malware to be downloaded again when compromised files are reintroduced
2
. This suggests that AI account hijacking may evolve beyond simple credential theft into more sophisticated attacks that exploit AI agent capabilities.WorriedAssociate7029 noted that while there have been several cases on Reddit of accounts being hacked to steals login sessions and tokens, Anthropic's customer service had previously seemed inadequate when handling refunds and account recovery. The new protective email and security measures appear to represent a shift in how the company addresses these threats
1
. As AI tokens become increasingly valuable commodities that can be resold, providers must implement robust detection systems to catch account theft before users face massive bills for services they never used.Summarized by
Navi
[1]
18 Mar 2026•Technology
26 Feb 2026•Technology

07 Mar 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
