Anthropic warns Claude users as malware steals login sessions and drains account usage
Infostealer malware can quietly hijack trusted browser sessions, leaving users exposed even when passwords remain secure, while unexpected usage spikes may offer an early warning of compromise.

- Sep 1, 2026,
- Updated Sep 1, 2026 5:00 AM IST
As AI applications become increasingly integral to daily workflows, the accounts that grant access to these tools are emerging as key targets for cybercriminals seeking to exploit trusted credentials. Security risks extend beyond traditional password theft and phishing schemes; pre-existing malware on a user's system can covertly harvest data stored by web browsers and software, concealing malicious operations.
An unexpected shift in account behaviour often serves as an early indicator of a compromise. Consequently, maintaining robust device security and routinely monitoring account usage are essential practices, especially for accounts tied to payment information or premium AI services. Highlighting these vulnerabilities, Anthropic has begun notifying select Claude users of potential security threats.
What Anthropic told affected Claude users
Anthropic said a bad actor is using common infostealer malware to steal Claude login sessions from infected computers and use up victims’ account limits. The company emailed affected users.
Must Read: Next space race could be fuelled by AI: How technology may reshape the orbital economy by 2030
One warning sign is when Claude usage limits appear to refill and then mysteriously drain while the account is not being used. Infostealers can copy authenticated browser sessions, allowing attackers to bypass passwords and two-factor authentication.
Malware behind the attacks
Anthropic said its investigation is ongoing and the affected computers were most likely already infected with general-purpose malware unrelated to Claude. The company said it has no reason to believe the malware came through Claude or was linked to anything users did on the platform.
Such malware can spread through downloads or malicious apps and harvest browser passwords, login cookies and credentials. Anthropic identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) among a small number of Mac cases. One affected user said they had downloaded a pirated game before the compromise.
What Anthropic is doing
For compromised accounts, Anthropic is signing users out, revoking stolen sessions, removing saved payment methods and refunding unauthorised charges. However, signing out only stops the stolen session; it does not remove malware from the device.
Anthropic is asking affected users to change their credentials, revoke active sessions and remove the malware before logging in again.
For Unparalleled coverage of India's Businesses and Economy – Subscribe to Business Today Magazine
As AI applications become increasingly integral to daily workflows, the accounts that grant access to these tools are emerging as key targets for cybercriminals seeking to exploit trusted credentials. Security risks extend beyond traditional password theft and phishing schemes; pre-existing malware on a user's system can covertly harvest data stored by web browsers and software, concealing malicious operations.
An unexpected shift in account behaviour often serves as an early indicator of a compromise. Consequently, maintaining robust device security and routinely monitoring account usage are essential practices, especially for accounts tied to payment information or premium AI services. Highlighting these vulnerabilities, Anthropic has begun notifying select Claude users of potential security threats.
What Anthropic told affected Claude users
Anthropic said a bad actor is using common infostealer malware to steal Claude login sessions from infected computers and use up victims’ account limits. The company emailed affected users.
Must Read: Next space race could be fuelled by AI: How technology may reshape the orbital economy by 2030
One warning sign is when Claude usage limits appear to refill and then mysteriously drain while the account is not being used. Infostealers can copy authenticated browser sessions, allowing attackers to bypass passwords and two-factor authentication.
Malware behind the attacks
Anthropic said its investigation is ongoing and the affected computers were most likely already infected with general-purpose malware unrelated to Claude. The company said it has no reason to believe the malware came through Claude or was linked to anything users did on the platform.
Such malware can spread through downloads or malicious apps and harvest browser passwords, login cookies and credentials. Anthropic identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) among a small number of Mac cases. One affected user said they had downloaded a pirated game before the compromise.
What Anthropic is doing
For compromised accounts, Anthropic is signing users out, revoking stolen sessions, removing saved payment methods and refunding unauthorised charges. However, signing out only stops the stolen session; it does not remove malware from the device.
Anthropic is asking affected users to change their credentials, revoke active sessions and remove the malware before logging in again.
For Unparalleled coverage of India's Businesses and Economy – Subscribe to Business Today Magazine
