Anthropic cracks down on hijacked user accounts mining AI tokens

← Back to the feed

Anthropic cracks down on hijacked user accounts mining AI tokens

The Register · 6 hours ago

Anthropic has begun clamping down on stolen Claude sessions after identifying a wave of infostealer malware being repurposed to hijack user accounts and exploit their paid AI usage. Rather than paying for their own access, criminals are using commodity malware to steal login credentials, session cookies and multifactor authentication data, then using this to run up premium Claude usage on victims' accounts. Anthropic has told at least one affected user it detected suspected fraud, logged them out and deleted their saved payment method, warning that AI account tokens are now a valuable target because they can be resold.

The case came to light via a Reddit user, WorriedAssociate7029, who shared an email from Anthropic after their social media accounts were compromised; they traced the infection to a cracked game download and later received a warning about an attempted API token theft, which Anthropic said it had blocked. Anthropic stressed the malware was unrelated to Claude itself and not some novel agentic AI threat, instead identifying well-known infostealers including Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer as responsible for harvesting Claude credentials and sessions alongside other stolen data. The user praised Anthropic's intervention but noted the company's customer service has historically been weak on refunds and account recovery for similar incidents.

  • Infostealer malware is being used to hijack Claude accounts and steal paid usage
  • Anthropic detected fraud, logged out a user and deleted their payment card
  • Known malware like Vidar, LummaC2 and RedLine are behind the thefts

AI Business Cybersecurity Markets Technology

Read the full article at the source →