Anthropic: infostealers hijacking Claude sessions to drain usage
On 30 August 2026 BleepingComputer reported Anthropic emails to affected Claude users: infostealer malware on already-compromised PCs stole active Claude login sessions, then used those sessions to access accounts and consume usage (including usage that appeared to refill then drain). Anthropic is signing affected users out, removing saved payment methods, and refunding charges it identifies as unauthorised. Anthropic says it has no reason to believe the malware was installed through Claude. It has identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs. Signing out stops the stolen session; it does not remove the malware. No CVSS. No public Anthropic advisory page at the time of writing; desk source is BleepingComputer quoting the company email.
- Product
- Anthropic Claude
- Versions
- session cookies / logged-in browser sessions
- Exploited in Australia?
- unknown
- Patch to
- Revoke sessions, remove malware, rotate credentials; Anthropic is signing affected users out
Primary: BleepingComputer (30 Aug 2026)
