Anthropic warns Claude self-serve accounts hit by infostealer session-cookie theft
Anthropic notified users that a threat actor used common infostealer malware—including Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer—to steal browser session cookies and replay them into paid Claude accounts, bypassing login and two-factor checks entirely. The company signed out affected sessions, removed stored payment methods, and refunded fraudulent charges tied to the campaign.