4 Sources
[1]
Anthropic boots users, wipes payment info to protect against malware attack - ZDNET
* Anthropic has alerted Claude users of an infostealer campaign. * Cybercriminals are now targeting usernames and passwords for AI platforms. * Refunds are being issued, but unless you clean up your device, it could happen again. Anthropic has alerted some Claude users to a new infostealing
[2]
Anthropic cracks down on hijacked user accounts mining AI tokens
Rather than paying for their own Claude usage, crims are using malware to steal access to other people's accounts. Aware of this issue, Anthropic has signed at least one affected user out and removed the saved payment method to stop stolen sessions being abused. According to an email shared by
[3]
Anthropic automatically signs out Claude users to protect them from hackers - Engadget
Anthropic has been signing users out of their accounts, deleting saved payment cards and refunding charges after attackers used stolen browser data to burn through victims' usage limits. That's according to an email the company sent to affected users last week, which has since been shared publicly
[4]
Hackers Target Claude Accounts With Malware That Steals Login Sessions | PYMNTS.com
Cyber Security News reported Monday (Aug. 31) that several information-stealing malware families, including Vidar, Lumma, StealC, RedLine and Acreed on Windows and Atomic Stealer on macOS, have been used to collect browser cookies, saved passwords and other credentials from infected devices. The
Share
Copy Link
Anthropic has begun automatically signing out Claude AI users and wiping payment information after detecting infostealer malware campaigns targeting AI platform credentials. Cybercriminals used stolen login sessions to drain usage limits and rack up unauthorized charges, prompting the AI company to take protective action across affected accounts.
Anthropic has taken decisive action against a malware attack targeting Claude AI users, automatically signing out affected accounts and removing stored payment information to protect against ongoing credential theft
1
. The AI company alerted users through email warnings after detecting cybercriminals using infostealer malware to hijack user accounts and consume their usage credits without authorization2
.The campaign marks a troubling evolution in cyber threats targeting AI platforms, as hackers now actively pursue AI platform credentials alongside traditional targets like financial records and cryptocurrency wallets. Rather than paying for their own Claude usage, cybercriminals are exploiting stolen login sessions to burn through victims' usage limits, potentially generating unauthorized charges on affected accounts
3
.
Source: ZDNet
The malware attack leverages well-known infostealer families including Vidar, Lumma, StealC, RedLine, and Acreed on Windows systems, alongside Atomic Stealer targeting a small number of Mac users
1
. These infostealers quietly collect browser cookies, saved passwords, session cookies, and other credentials from infected devices, with Claude sessions appearing among the stolen data targets4
.The threat proves particularly dangerous because stolen session cookies allow attackers to impersonate already-authenticated users, bypassing traditional security measures. "Because the attackers can reuse an existing session, traditional login protections such as multifactor authentication may not prevent the takeover," according to security analysis
4
. Anthropic identified cases where attackers consumed paid Claude usage after account owners had stopped using the service, with usage limits appearing to refill and drain while victims weren't actively using Claude1
.Anthropic clarified that the malware infections stem from users' own devices rather than any breach at the company itself. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company stated in emails to affected users
2
. The infections appear concentrated on Windows and Mac PCs, with no current evidence involving phones or tablets1
.One affected Reddit user admitted the infection likely originated from downloading a cracked game, highlighting how risky behavior like pirating software or downloading illegal content creates vulnerability to these attacks. "I got fooled like a rookie by downloading a cracked game. Never again," the user acknowledged
2
. This underscores that users engaging in such activities risk their privacy, security, and devices, though Anthropic is still providing refunds for unauthorized charges despite users' role in the infections.A distinct but related threat emerged when attackers exploited Claude's own infrastructure to distribute malware. Between July 21 and July 22, cybercriminals used sponsored Bing ads to direct users searching for the Claude desktop application to a malicious Claude Artifact hosted on the legitimate claude.ai domain
4
. The fake installer deployed SectopRAT, a remote-access Trojan capable of harvesting browser credentials, session cookies, files, and payment information4
.
Source: Engadget
Cybersecurity firm Huntress identified at least 29 compromised organizations and roughly 7,100 downloads before Anthropic removed the malicious page. The incident reveals attackers have begun hiding malicious instructions in files used by Claude's agent, potentially allowing malware to be downloaded again when compromised files are reintroduced
4
.Related Stories
Anthropic's protective measures—forcing sign-outs, removing payment methods, and issuing refunds—do not eliminate the underlying malware from infected devices
3
. Users must take immediate action by removing any suspicious, new, or cracked software from their systems and running deep malware scans to detect and eliminate infostealers lurking on their machines1
.Affected users will need to sign back into their accounts and re-add payment information after Anthropic's forced logout. If strange charges appear that haven't been refunded, users should contact Claude support directly. One affected user praised Anthropic's response, noting "There have been several cases on Reddit in the past of accounts being hacked to steal tokens, and Anthropic's customer service seems pretty dreadful when it comes to refunds and account recovery. This email appears to be new, and measures have finally been put in place to protect AI users"
2
.
Source: PYMNTS
The emergence of hijacked user accounts mining AI tokens signals a fundamental shift in what cybercriminals consider valuable. AI tokens can be resold on underground markets, making them attractive targets for theft
2
. The security risks extend beyond individual users to businesses adopting AI tools, as compromised accounts could expose sensitive corporate data processed through Claude.This development adds urgency to existing security concerns surrounding AI platforms. In July, Alibaba barred employees from using Anthropic's AI tools at work and placed Claude Code on a high-risk software list, though this followed separate allegations about model capability extraction rather than malware concerns
4
. The malware attack demonstrates that as AI platforms become more integral to daily workflows, they will increasingly attract sophisticated cyber threats targeting their unique value propositions.Watch for potential increases in similar attacks targeting other AI platforms as cybercriminals recognize the profitability of stolen AI credentials. Organizations deploying AI tools should implement additional monitoring for unusual usage patterns and educate users about the expanding threat landscape now encompassing AI platform credentials alongside traditional security targets.
Summarized by
Navi
[2]
09 Sept 2026•Technology

08 Jul 2026•Technology

26 Feb 2026•Technology

1
Technology

2
Technology

3
Science and Research
