Malware harvests Claude session cookies in widespread attack

← Back to the feed

Malware harvests Claude session cookies in widespread attack

Engadget · 1 day ago

Anthropic has been forcibly signing users out of Claude accounts, deleting stored payment cards and issuing refunds after criminals used malware-stolen login sessions to run up unauthorised usage on victims' accounts. The company told affected users in an email, later shared on Reddit, that infostealer malware on their own computers—not any breach of Anthropic's systems—had harvested active Claude session cookies, allowing attackers to hijack accounts without needing passwords or two-factor codes.

Anthropic has linked the hijackings to six malware families, including Vidar, Lumma, StealC, RedLine and Acreed on Windows, and Atomic Stealer on a small number of Macs; none specifically targets Claude, but all harvest browser cookies that can be replayed to impersonate a logged-in user. Anthropic advises affected users to remove the malware first, then secure the associated email account with a new password and two-factor authentication before re-adding payment details. Security researchers have noted a growing black market in stolen AI account credentials, including for ChatGPT and Gemini, with hijacked logins resold cheaply through so-called "transfer station" proxy services.

  • Malware stole Claude login cookies, letting hackers bypass passwords and 2FA
  • Anthropic force-logged out victims, deleted cards, refunded fraudulent charges
  • Users must remove malware and reset email security before restoring accounts

AI Cybersecurity Technology

Read the full article at the source →

Originally published by Engadget as “Anthropic automatically signs out Claude users to protect them from hackers”.