Anthropic is locking some users of its Claude AI model out of their accounts after their systems were compromised by infostealing malware that allowed the hackers to hijack login sessions and consume their usage.
In emails sent to affected users, Anthropic officials wrote that attackers used common infostealers like Vidar, LummaC2, StealC, Redline, and Acreed on Windows systems and another, Atomic Stealer, on a small number of Macs.
“It’s general-purpose malware that typically arrives with an unofficial download or a malicious app, and it quietly copies saved passwords, login cookies in browsers, and credentials for other apps running locally,” they wrote in the message, which a user posted on Reddit. “Your Claude session was likely one of the many things it collected.”
The incidents are another example of an attack method that is becoming more common, with bad actors stealing session hijacking tokens and cookies rather than focusing credentials, enabling them to bypass authentication and not set off warnings or alerts.
Downloaded a Cracked Game
Anthropic detected the intrusion on some Claude accounts and, in response, removed the users’ payments cards that were on file and signed them out of their sessions. The vendor also refunded charges there were deemed unauthorized.
The users were told to log back in and re-enter their card information. They also warned that taking those steps will stop the stolen sessions, but that the malware will remain in their systems. Users were advised to scan for and remove the infostealer malware.
In a message that came with the posted Anthropic emails, the affected user on Reddit admitted that they “got fooled like a rookie by downloading a cracked game,” which likely led to the infostealer infection.
Changing Passwords Wasn’t Enough
They wrote that their social media accounts were hacked and were able to find the virus by using Anthropic’s Opus 5 Max model. They also changed their passwords, but a few days later was warned by the AI vendor that there had been an attempt to steal their tokens through the API. The attempt fail – the user was logged into Anthropic through Google, which includes two-factor authentication (2FA), but the bad actors still stole of their Google Chrome credentials.
That included cookies and session ID, which allowed the attacker to bypass the 2FA security.
“As an emergency measure, I removed all active sessions from my Google accounts (which I should have done from the start) and changed my passwords again,” they wrote.
Stealing Capacity for Running Attacks
“The criminals’ likely motive is to use paid Claude capacity for free,” analysts with Malwarebytes wrote in a blog post. “The account and any exposed data could also be useful for fraud, social engineering, or follow-on attacks.”
The attackers could use the capacity stolen from victims in multiple parts of their operation, according to Malwarebytes, from writing and refining phishing and scam content and building the infrastructure for their nefarious campaigns to developing or obfuscating malware to analyzing stolen information.
Infostealers are Key
The attackers’ methods have become more commonplace over the past year or two. They are shifting from targeting passwords to aiming for sessions, according to Huntress researchers. Infostealer malware is a key part of the equation.
“Between 2020 and 2025, cybercriminal tactics have evolved rapidly,” the researchers wrote. “The traditional model of stealing usernames and passwords has been replaced by a far more dangerous threat: session hijacking.”
They use infostealers to harvest browser sessions tokens and authentication cookies, they wrote. Those tokens and cookies give the bad actors unauthorized access to email, cloud services, developer platforms, and critical infrastructure, all without the need for passwords or triggering alerts from multifactor authentication (MFA) tools.
Feeding the Underground Economy
“These session tokens and employee credentials are sold on dark web black markets,” the researchers wrote. “Then the stolen data is replayed using automation tools, which lets attackers bypass security controls, move laterally, and launch ransomware, extortion, or IP theft campaigns in under an hour.”
The growing economy around infostealing malware makes such attacks cheap and fast, they wrote.
“Logs containing valid session tokens for tools like Microsoft 365 or Slack sell for as little as $5 on dark web markets and as much as $500 for high-value targets,” they wrote. “Modular add-ons like browser fingerprint bundles and password manager vaults let attackers stack access and maximize ROI. One raw log. One hour. Full environment access.”
The methods used to get by traditional protections like MFA and put a focus on the need for organizations to treat session data as privileged access, the researchers wrote. Enterprises also should implement short-lived tokens and monitor their systems for questionable behaviors.