Anthropic signs Claude users out, deletes cards after infostealer malware hijacks sessions
Anthropic forced sign-outs, removed saved payment cards and refunded charges after infostealer malware stole active Claude login sessions from users' computers.
The email attributes the account takeovers to infostealer malware on customers' own computers, not to a breach of Anthropic's systems. In the affected cases, the malware harvested active Claude login sessions from users' browsers. "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," the company wrote. Anthropic said it forced sign-outs of affected sessions, removed the card on file and refunded any extra usage charges tied to the activity. It also warned that these steps stop the stolen sessions but do not remove the malware from the affected machine.
Anthropic has so far linked the hijacked sessions to six infostealer families: Vidar, Lumma, StealC, RedLine and Acreed on Windows, and Atomic Stealer, or AMOS, on a small number of Macs. The malware is general-purpose rather than built specifically for Claude, and usually arrives bundled with malicious downloads. Once running, it can scoop up saved passwords and browser cookies. In these incidents, it copied Claude session cookies, the tokens a browser keeps after login so the user does not have to enter a password on each page load. An attacker replaying a stolen cookie can enter the victim's authenticated session without triggering password or two-factor authentication requests.
Anthropic's recommended fix is to remove the malware before logging back in to Claude, then secure the email address attached to the account with a new password and two-factor authentication. Payment methods should be re-added only after those steps are complete.
The broader market for hijacked AI accounts adds context to the threat. Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told Axios in August that criminals are trafficking credentials for Claude, ChatGPT and Gemini. Researchers at Palo Alto Networks' Unit 42 have traced hijacked accounts to proxy services known as transfer stations, which pool stolen credentials and resell access to AI services at prices well below retail.
Anthropic does not publish exact figures for Claude usage limits, but every prompt carries a compute cost, and the company absorbs that cost when a stolen session is used. An attacker with a card on file can also buy extra usage on the victim's account, which is why Anthropic removed saved payment methods instead of only terminating sessions. The company doubled paid Claude Code rate limits in May after demand repeatedly outran capacity.