Anthropic forces logouts after malware hijacks Claude sessions

4 sources
  • Anthropic warned Saturday that attackers used common infostealer malware to steal Claude session cookies and consume victims' paid usage.
  • The company forcibly signed out affected users, wiped saved payment cards, and identified six malware families including Vidar, LummaC2, and RedLine.
  • Two-factor authentication offered no protection because attackers replayed already-authenticated sessions, bypassing the login process entirely.
Sources (4)
  1. 1 Anthropic warns infostealer malware is hijacking Claude sessions to drain usage www.bleepingcomputer.com
  2. 2 Anthropic says infostealer stole Claude login sessions, wipes users' saved cards pasqualepillitteri.it
  3. 3 Anthropic Warns Hackers Are Stealing Claude Sessions To Hijack Accounts www.searchenginejournal.com
  4. 4 Claude Session Theft: Critical Anthropic Warning www.secnews.gr