Anthropic Users Hit by Infostealer Attacks, Session Thefts

Refract AI Intelligence Digest

BLUF

Threat actors compromised Anthropic user accounts via infostealer malware targeting session tokens.

NEWS

A threat actor deployed various infostealers to harvest session information from victims' devices. This activity resulted in unauthorized access to Claude AI accounts, though the total scope of the breach remains unconfirmed.

Why I Care

This highlights the risk of session hijacking in AI platforms, potentially exposing sensitive prompts and data. Enterprise users relying on Claude for confidential work are at high risk of data leakage or prompt injection attacks via compromised accounts.

Next Steps

Users should immediately revoke active sessions and change passwords within their Anthropic dashboard. Organizations should enforce multi-factor authentication and monitor for unusual API usage patterns starting today.

A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Back to Blog Listing

Source: Dark Reading ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.