Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.
The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email sent to an affected user, who shared it on Reddit.
"If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," Anthropic warned.
Anthropic sending emails to affected users
Source: Reddit
It is also worth noting that infostealers can copy an already authenticated browser session, which means the attacker may not need to go through the normal password and 2FA login process again.
Anthropic links attacks to Vidar, LummaC2, StealC, RedLine and other infostealers
In the email, which is also being sent out to other compromised account holders, Anthropic says its investigation is ongoing, but computers were likely already infected with general-purpose infostealer malware.
"We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company stressed.
... continue reading