Anthropic Users Hit by Infostealer Attacks, Session Thefts
BLUF
Threat actors compromised Anthropic user accounts via infostealer malware targeting session tokens.
NEWS
A threat actor deployed various infostealers to harvest session information from victims' devices. This activity resulted in unauthorized access to Claude AI accounts, though the total scope of the breach remains unconfirmed.
Why I Care
This highlights the risk of session hijacking in AI platforms, potentially exposing sensitive prompts and data. Enterprise users relying on Claude for confidential work are at high risk of data leakage or prompt injection attacks via compromised accounts.
Next Steps
Users should immediately revoke active sessions and change passwords within their Anthropic dashboard. Organizations should enforce multi-factor authentication and monitor for unusual API usage patterns starting today.
Source: Dark Reading ·