Accounts were used by strangers without a single password ever being cracked. In August 2026, Anthropic confirmed that Claude login sessions had been lifted from the computers of users infected with infostealer malware, and that outside parties had been using those accounts. The company has signed the affected accounts out, removed the saved payment cards, and is refunding charges it identifies as unauthorized.

What Was Stolen Was the Session, Not the Password

The target in this campaign was an already-authenticated session rather than a password.

Once you log in, the site hands your browser a session cookie so you do not have to re-authenticate on every click. Infostealer malware simply copies that cookie. When an attacker replays it, the server sees nothing but a user who has already completed login.

That is why neither two-factor authentication nor single sign-on holds the line here. Two-factor authentication guards the front door, but if the pass handed out after the door is carried off, the whole authentication step is bypassed. This is the structural reason session theft has been overtaking password theft in recent account compromises.

The Tell Is Usage That Drains While You Are Away

The notice Anthropic sent to affected users spells out how to spot the damage. Usage limits appear to refill, then drain while you are not using Claude. If that behavior sounds familiar, this campaign is the likely cause.

Attackers used the stolen sessions to reach paid accounts and burn through the subscriber's allowance. Anthropic's own systems detected the suspicious activity, removed the card on file for the affected accounts, and signed out the sessions involved.

The company states plainly that it has no reason to believe the malware is related to Claude or arrived through Claude. The infections were on computers; phones and tablets do not appear to have been involved.

Five Windows Families and One for macOS

The malware Anthropic has identified in this campaign so far includes five Windows families: Vidar, Lumma (LummaC2), StealC, RedLine and Acreed. Atomic Stealer (AMOS) was also found on a small number of Macs.

None of these are built to target one company. They are general-purpose infostealers that arrive alongside an unofficial download or a malicious app, then quietly copy saved browser passwords, login cookies, and credentials for other apps running locally. The Claude session was just one item in the haul. Anthropic's reading is that a bad actor then began picking Claude sessions out of what had been collected.

One infection route has surfaced as well. A user who posted Anthropic's notice on social media traced the infection back to downloading a pirated game from a Russian-language underground forum.

Recovery in the Wrong Order Accomplishes Nothing

Anthropic emphasizes the order of operations. Signing out stops the stolen sessions, but the malware stays on the machine. Log back in without cleaning it up and the new session is simply collected too.

The company's recommended sequence:

  1. Scan the machine and remove any malware found
  2. Change the password on the email account used for Claude and enable two-factor authentication
  3. Update any passwords saved in the browser, and check card statements if payment details were stored there
  4. Re-add a payment method if you intend to keep using the service

Beyond Claude, users are advised to clear active sessions on other online services, sign out, and log back in. The passes lifted from that machine were unlikely to be limited to Claude.

Existing plans continue until the end of the current billing period, after which a payment method must be added again. Anthropic notes it may sign users out again if it detects further suspicious activity.

Watch for Copycat Emails

A moment when official warning emails are circulating widely is also an opportunity for attackers. It is worth assuming that fake emails impersonating Anthropic and using this incident as a pretext will follow.

The rule of thumb does not change. Reach the official site through your own bookmark or the address bar rather than a link inside the email. That alone defeats most opportunistic phishing.

Summary

Measured in money alone, having an AI subscription quietly drained is not the worst outcome available. But it is a byproduct of a machine that is infected with an infostealer, and the same haul may well contain banking or cloud service credentials. If something looks off in your Claude usage history, start with an inspection of the machine rather than with account recovery.

※The thumbnail image is an AI-generated illustration.