Anthropic Cracks Down on Claude Account Hijacking as Cybercriminals Steal AI Tokens

2 Sources

Share

Cybercriminals are using infostealer malware like Vidar, Lumma, and StealC to hijack Claude accounts and steal AI tokens without paying. Anthropic has responded by signing out affected users, removing stored payment methods, and refunding fraudulent charges. The attacks exploit session cookies to bypass multifactor authentication.

Cybercriminals Target Claude Accounts to Steal AI Tokens

Anthropichas identified a wave of account hijacking targeting Claude accounts, where cybercriminals use infostealer malware to steal login credentials and consume premium AI services without paying. Rather than targeting Anthropic's infrastructure directly, attackers are deploying well-known infostealer malware including Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on macOS to collect browser cookies, saved passwords, and session cookies from infected devices

1

2

. The threat actor then uses this stolen information to access hijacked user accounts and rack up charges for premium Claude usage on someone else's dime.

Source: PYMNTS

Source: PYMNTS

The malware steals login credentials and session data that allows attackers to bypass traditional security measures. Because stolen session cookies enable attackers to impersonate already-authenticated users, even multifactor authentication cannot prevent these account takeovers. Anthropic has detected cases where attackers consumed paid Claude usage after legitimate account owners had stopped using the service, making the fraud harder to detect initially

2

.

How AI Account Hijacking Works

The attack chain begins when users unknowingly install infostealer malware on their devices. One Reddit user, WorriedAssociate7029, admitted to downloading a cracked game that infected their system. The malware collected credentials from multiple accounts, including social media and Google account credentials, along with cookies and session IDs

1

. Days later, Anthropic detected the attempted fraud and sent a warning email explaining that a bad actor had started picking Claude sessions out of the collected data and using them to steal AI tokens through the API.

Anthropicmade clear in communications to affected users that the credential theft has nothing to do with Claude itself. The company emphasized that this is traditional infostealer malware being repurposed for a new target: valuable AI tokens that can be resold on underground markets

1

. As AI services become more expensive and widely adopted, cybercriminals have identified AI tokens as a lucrative commodity worth stealing.

Anthropic's Response to Protect Users

Upon detecting suspicious activity, Anthropic has taken proactive measures to protect affected accounts. The company has been signing users out of their accounts and removing stored payment methods to prevent further fraudulent charges. In the case shared by WorriedAssociate7029, Anthropic successfully blocked the attempted fraud before significant damage occurred

1

.

Anthropichas also committed to refunding confirmed fraudulent charges for victims of these attacks. However, the company has warned users that while it can secure Claude accounts, these protective measures do not remove malware from infected devices

2

. Users must take additional steps to clean their systems and secure all compromised accounts, not just Claude.

Broader Security Threats Facing AI Platforms

A separate campaign tracked by cybersecurity firm Huntress revealed another attack vector exploiting Claude's infrastructure. Between July 21 and July 22, attackers used sponsored Bing advertisements to direct users searching for the Claude desktop application to a malicious Claude Artifact hosted on the legitimate claude.ai domain. This fake installer deployed SectopRAT, a remote-access Trojan capable of harvesting browser credentials, cookies, files, and payment-card information. Huntress identified at least 29 compromised organizations and roughly 7,100 downloads before Anthropic removed the malicious page

2

.

The activity highlights growing cybersecurity concerns for businesses adopting AI tools. Attackers have begun hiding malicious instructions in files used by Claude's agent, potentially allowing malware to be downloaded again when compromised files are reintroduced

2

. This suggests that AI account hijacking may evolve beyond simple credential theft into more sophisticated attacks that exploit AI agent capabilities.

WorriedAssociate7029 noted that while there have been several cases on Reddit of accounts being hacked to steals login sessions and tokens, Anthropic's customer service had previously seemed inadequate when handling refunds and account recovery. The new protective email and security measures appear to represent a shift in how the company addresses these threats

1

. As AI tokens become increasingly valuable commodities that can be resold, providers must implement robust detection systems to catch account theft before users face massive bills for services they never used.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved