Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Refract AI Intelligence Digest

BLUF

Infostealer malware is compromising Claude accounts by hijacking active sessions to drain usage quotas.

NEWS

Anthropic notified users that infostealer infections on endpoint devices are extracting valid session tokens for their AI platform. Attackers utilize these stolen credentials to access accounts and consume paid usage limits without authorization. This incident highlights the risk of session hijacking even when passwords remain secure.

Why I Care

This affects all Claude users with endpoint malware, leading to direct financial loss through drained credits and potential data exposure within chat histories. It underscores that strong passwords are insufficient if session tokens are compromised by local malware.

Next Steps

Users should immediately revoke active sessions in their account settings and run full endpoint scans to remove infostealers. Organizations should enforce multi-factor authentication where possible and monitor usage anomalies for unexpected spikes.

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.