Advisory
Published 2026-08-30
Verified 2026-09-19

Anthropic: infostealers hijacking Claude sessions to drain usage

On 30 August 2026 BleepingComputer reported Anthropic emails to affected Claude users: infostealer malware on already-compromised PCs stole active Claude login sessions, then used those sessions to access accounts and consume usage (including usage that appeared to refill then drain). Anthropic is signing affected users out, removing saved payment methods, and refunding charges it identifies as unauthorised. Anthropic says it has no reason to believe the malware was installed through Claude. It has identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs. Signing out stops the stolen session; it does not remove the malware. No CVSS. No public Anthropic advisory page at the time of writing; desk source is BleepingComputer quoting the company email.

Product
Anthropic Claude
Versions
session cookies / logged-in browser sessions
Exploited in Australia?
unknown
Patch to
Revoke sessions, remove malware, rotate credentials; Anthropic is signing affected users out

Primary: BleepingComputer (30 Aug 2026)

ai identity