Anthropic is signing Claude users out after infostealers stole live login sessions
Anthropic is warning some Claude users that infostealer malware on their PCs stole active Claude login sessions. The company is signing affected users out, removing saved payment methods, and refunding charges it identifies as unauthorized.
Mayank Parmar at BleepingComputer has the email, shared on Reddit. Anthropic wrote that a bad actor is “using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” If usage limits “looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”
A login cookie is a leftover ticket in the browser that says you already proved who you are. Infostealer malware copies that ticket off the machine. The attacker then walks into Claude without the password and without the second-factor code.
Anthropic can tear up the stolen ticket and put money back on the card. It cannot wipe the program that will steal the next ticket the next time the user logs in.
That is not a Claude breach.
Anthropic says it has no reason to believe the malware is related to Claude, installed through Claude, or related to anything the user did with Claude. The typical path is unofficial downloads or malicious apps. The Claude session was one item in a local haul of passwords, cookies, and other app credentials. A bad actor started picking Claude sessions out of that haul.
Anthropic named the families: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on a small number of Macs. Pierluigi Paganini at Security Affairs has the same email spine.
Phones and tablets do not appear to have been involved.
Existing plans continue until the current billing period ends. Then the user has to put a card back on file. Anthropic may sign the account out again if it sees more suspicious activity.
“Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware. If it’s still on your computer, your next login session could be stolen the same way.”
I treat the refund as a billing cleanup.
The next login still lands on the same hard drive.
