Infostealer Malware Is Hijacking Claude Sessions: Anthropic Signs Users Out, Wipes Payment Cards, Issues Refunds
Anthropic is warning Claude users that commodity infostealers — Vidar, LummaC2, StealC, RedLine, Atomic Stealer — are harvesting authenticated browser sessions, bypassing MFA entirely, and draining account usage; the company is force-signing-out victims, deleting saved cards, and refunding unauthorized charges.
If your Claude usage limits “looked like they refilled and then drained while you weren’t using Claude,” Anthropic has a message for you: your computer is probably infected, and someone has been using your AI subscription from afar.
On August 30, 2026, BleepingComputer reported that Anthropic has begun emailing affected Claude users with an unusually specific warning. A bad actor is using common infostealer malware to steal Claude login sessions directly from people’s computers, then replaying those sessions to access Claude accounts and consume their usage. In response, Anthropic is taking the kind of remediation steps users normally associate with a bank, not a chatbot company: force-signing victims out of Claude, removing saved payment methods from compromised accounts, and refunding charges it identifies as unauthorized.
How the attack works — and why MFA doesn’t help
The mechanics are simple, which is exactly what makes them nasty. Infostealer malware — commodity criminal tooling that arrives through pirated software, trojanized downloads, and malicious installers — hoovers up everything of value stored locally on an infected machine: browser passwords, autofill data, login cookies, and credentials belonging to other applications. Among the things it collects are authenticated session tokens: the cookies that let your browser skip the login flow because you already proved who you are.
Session tokens are valuable precisely because they render the entire authentication stack irrelevant. An attacker holding a live session doesn’t need your password. They don’t need your one-time code. They don’t need to defeat your single sign-on. As the AI Governance Institute’s analysis of the incident put it, the attack “operates on a valid, already-authenticated session,” and therefore “bypasses password controls, multi-factor authentication, and single sign-on entirely.” Anthropic’s email to one victim stressed the same point: infostealers can copy an already-authenticated browser session, so the attacker never has to go through the normal password and 2FA process again.
Anthropic’s investigation is ongoing, but the company was careful about attribution of the infection itself: “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude.” The malware typically arrives through downloads or malicious apps and steals information stored locally. “Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them.”
In other words: the theft was indiscriminate; the monetization is now targeting AI accounts specifically.
The named malware families
Anthropic has identified multiple malware strains in the campaign:
- Vidar — a long-running Windows infostealer sold as a service, known for harvesting browser data, cookies, and cryptocurrency wallets
- LummaC2 (also seen as Lumma) — a fast-growing MaaS (malware-as-a-service) stealer frequently distributed through cracked-software lures and fake installer pages
- StealC — a newer Windows stealer that emerged in 2023 and has become a staple of criminal markets
- RedLine — one of the most widely deployed stealers of the past several years, implicated in countless credential-theft campaigns
- Acreed — an additional Windows family identified in Anthropic’s notifications
- Atomic Stealer (AMOS) — the macOS infostealer, found on “a small number of Macs,” confirming that this is not a Windows-only problem
All of these are commodity tools, widely available in criminal markets. None of them were built to attack Claude. That’s the unsettling part: attacking AI accounts required no new capability, only the realization that stolen sessions for claude.ai are now worth picking out of the pile.
One Redditor who received the notification confirmed they had downloaded a pirated game — a textbook infection vector that needed no AI-specific lure at all.
What Anthropic is doing about it
The remediation playbook Anthropic described is blunt but limited:
- Revoke the stolen sessions — signing affected users out of Claude stops the stolen session tokens from working.
- Remove saved payment methods — so a hijacked account can’t be used for further unauthorized purchases.
- Refund unauthorized charges — Anthropic says refunds for identified fraudulent charges have “already been applied,” so affected users don’t need to do anything on that front.
But Anthropic was equally clear about the limits of what it can do from the server side: “Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware. If it’s still on your computer, your next login session could be stolen the same way.” The company is urging affected users to change credentials, revoke other sessions, and actually remove the malware from their machines.
The company has not disclosed how many accounts were affected or how it identifies compromised sessions — a gap the AI Governance Institute flagged as material for enterprise customers, who “cannot independently verify whether their sessions were compromised or confirm the scope of any unauthorized access.”
Why this matters beyond billing fraud
For individual users, the worst case so far looks like a drained subscription and some refunded charges. For enterprises, the exposure is bigger. An active Claude session isn’t just a billing relationship — it’s a window into whatever that session has touched: confidential documents uploaded for analysis, internal code pasted for debugging, sensitive prompts, conversation history. The AI Governance Institute’s incident note warns that “the exposure extends beyond billing fraud to the content of active sessions,” and recommends that organizations audit browser-based Claude sessions on shared endpoints, remove stored billing credentials from team accounts, and isolate API-key access from browser-session access.
There’s also a timing irony that’s hard to miss. This disclosure lands days after more than 100 companies — Anthropic included — signed an open letter warning that AI-enabled attacks on critical infrastructure are imminent. The letter’s framing positioned AI primarily as an emerging offensive threat. The infostealer campaign is a reminder of the mirror image: AI accounts are now valuable enough that ordinary criminal malware has learned to hunt them, and the standard authentication advice — turn on MFA, use SSO — offers no protection at all against a stolen session cookie.
The uncomfortable takeaway
The AI industry has spent 2026 locked in debates about rogue agents, autonomous hackers, and models escaping sandboxes. Meanwhile, the first mass monetization of stolen AI access arrived through the oldest, dumbest channel imaginable: pirated software, commodity stealers, and session replay. No jailbreak required.
The practical advice is boring and effective: don’t install pirated software; treat any machine that does double duty as a browsing/downloading machine as untrusted for sensitive sessions; use dedicated endpoints or API keys for anything that touches confidential data; and if Anthropic emails you saying you’ve been signed out for your own protection — believe them, and clean the machine before logging back in. Because the next session you create will be harvested exactly the same way.
Session hijacking isn’t a new attack. But claude.ai sessions becoming a liquid criminal asset — liquid enough that attackers sort stolen logs to find them — is a genuine 2026 milestone in the mainstreaming of AI.
Sources
- [1] https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/
- [2] https://aigovernance.com/news/infostealer-malware-bypasses-mfa-to-hijack-claude-accounts
- [3] https://www.reddit.com/r/claude/comments/1vf48yc/i_woke_this_morning_and_found_out_anthropic/