TechNewsReel
Live

Anthropic combats account hijackings targeting AI usage quotas

The AI company implemented security measures after attackers used infostealer malware to bypass MFA and steal computing resources.

TechNewsReel Newsroom · August 31, 2026

Anthropic has launched a crackdown on a wave of account hijackings designed to steal AI computing resources from legitimate users. The company implemented new security measures after discovering that attackers were using stolen session tokens to bypass traditional login protections.

According to reports from The Register and other security sources, attackers deployed commodity infostealer malware—including Vidar, Lumma, StealC, RedLine, Acreed, and AMOS—to extract authenticated session cookies directly from users' devices. By stealing these tokens, cybercriminals were able to impersonate users and gain full access to their accounts without needing passwords or multi-factor authentication (MFA). Once inside, the attackers consumed the paid usage quotas of these accounts, effectively freeloading on the computing power paid for by legitimate subscribers.

The mechanics of session theft

This attack leverages a technique known as session hijacking or cookie theft. Unlike traditional phishing, which seeks to steal a password, session hijacking targets the "cookie" a browser stores after a user has already successfully logged in. Because the server sees a valid session token, it assumes the requester is the authenticated user, rendering MFA and strong password policies irrelevant. In the context of large language models (LLMs), these sessions provide a direct gateway to expensive API credits and subscription-based usage limits that would otherwise require a paid account.

Why AI quotas are targets

This trend underscores a shift in the cybercrime landscape where AI service quotas are becoming valuable commodities. As the demand for high-performance AI increases, the ability to access paid tiers of LLMs without payment provides a significant advantage to bad actors. This incident demonstrates that session-level vulnerabilities can lead to direct resource theft, creating financial losses for service providers and depleting the available quotas for paying customers.

Anthropic's response and next steps

To mitigate the breach, Anthropic has taken steps to sign out affected sessions and remove saved payment methods to block further unauthorized access. While the company has moved to secure these accounts, the incident highlights a persistent vulnerability in how web-based services handle long-term sessions. Security experts continue to monitor whether these stolen tokens are being aggregated and sold as a service on the dark web, a common practice for infostealer operators.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.