Anthropic Warns Claude Users of Malware Stealing Login Sessions
What Happened
Anthropic has warned some Claude AI users that infostealer malware is stealing active browser login sessions, allowing attackers to access accounts and consume usage limits without needing passwords or two-factor authentication. The company said the attacks stem from malware already present on infected devices, not from Claude itself, and has responded by signing affected users out, removing saved payment methods and refunding unauthorized charges.
Key Takeaways
The incident highlights a growing cybersecurity threat where hackers bypass passwords and MFA by stealing authenticated browser sessions, underscoring the importance of device security alongside account security.