toolcall.
ToolsAug 31, 2026, 14:28 UTC

Anthropic warns Claude users about stolen login sessions

Infostealer malware on user devices can copy active sessions, letting attackers drain Claude usage without a normal login.

Anthropic is warning some Claude users that infostealer malware on their own computers stole active Claude login sessions. According to an email quoted by BleepingComputer, attackers used those sessions to access accounts and consume usage, even when the user was not actively using Claude.

The important detail is that this is not described as a Claude breach. Anthropic says the malware was likely already present on affected devices and could collect browser passwords, cookies and app credentials. A copied session can let an attacker bypass the normal password and two-factor flow because the browser already looks authenticated.

Anthropic says it is signing affected users out, revoking compromised sessions, removing saved payment methods and refunding charges it identifies as unauthorized. The company also warns that signing out only stops the stolen session; it does not remove malware from the machine, so a new login could be stolen again if the device remains infected.

For Claude users, the practical advice is simple: if usage refills and drains unexpectedly, treat it as a possible device compromise, not just an account glitch. Change passwords from a clean device, revoke active sessions where possible, check payment methods and run a serious malware cleanup before logging back in.

Sources

Mentioned

anthropicclaudecybersecurityprivacysecurity