TechNewsReel
Live

Anthropic Purges Sessions After Infostealer Malware Hijacks Claude Accounts

The AI company forced sign-outs and issued refunds after attackers used stolen browser cookies to bypass 2FA.

TechNewsReel Newsroom · September 3, 2026

Anthropic has proactively signed out affected users and deleted saved payment methods after discovering that infostealer malware was harvesting active login sessions from user devices. The company issued refunds to those impacted by unauthorized charges resulting from the hijacks.

According to Anthropic, attackers utilized stolen browser cookies—known as session tokens—to replay active sessions. This technique allowed criminals to bypass both passwords and two-factor authentication (2FA) prompts, granting them full access to accounts. Once inside, attackers exhausted usage limits and made unauthorized charges. Anthropic clarified that the security failure originated from local malware infections on individual computers rather than a breach of the company's own internal systems.

The Malware Landscape

Anthropic identified six specific malware families responsible for the session thefts. On Windows systems, the company flagged Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed. macOS users were targeted by Atomic Stealer (AMOS).

In an email to affected users, Anthropic noted that a primary indicator of compromise was erratic usage patterns, stating, "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause."

The AI Gray Market

This incident is part of a broader trend involving the underground trade of hijacked AI accounts, including those for Claude, ChatGPT, and Gemini. Cybercriminals are increasingly using "transfer stations"—proxy services that pool stolen credentials—to resell access to premium AI services. These accounts are sold at a significant discount compared to retail prices, capitalizing on the high compute costs and strong market demand for advanced AI models.

Why Session Theft Matters

The attack highlights a critical vulnerability in modern web session management. While 2FA is widely regarded as a gold standard for account security, it only protects the initial login process. Once a session token is generated and stored in a browser, it becomes a high-value target; if stolen, it provides a "skeleton key" that renders 2FA irrelevant.

Furthermore, the rise of transfer stations demonstrates a shifting economic incentive for hackers. Rather than simply stealing personal data, criminals are now treating AI compute resources as a commodity to be harvested and flipped in a gray market.

What's Next

Users are encouraged to scan their devices for the identified malware families and rotate their credentials. While Anthropic has taken immediate remedial action by purging sessions, the industry continues to grapple with how to secure long-lived session tokens against sophisticated infostealers. Security researchers will likely monitor whether these "transfer station" models expand to target other high-cost SaaS subscriptions beyond AI services.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.