**Cyberattacks on Anthropic Users Expose Vulnerability in Session Security**
A sophisticated threat actor has been exploiting a vulnerability in session security, targeting users of the AI company Anthropic’s platform, Claude. The attacker used infostealer malware to steal login sessions and access associated accounts, highlighting the growing trend of attackers shifting from traditional password theft to more nuanced tactics.
The attacks were discovered when affected users received email notifications from Anthropic, which had proactively signed them out of their Claude accounts after detecting suspicious activity. The company’s investigation found that the threat actor used general-purpose infostealers, such as Vidar and LummaC2, which had likely been installed on users’ systems through a malicious app or unofficial download.
Infostealer malware works by stealing sensitive information from a system, including login sessions, authentication tokens, and other credentials. In this case, the attacker used these stolen sessions to access Claude accounts without having to defeat the authentication controls protecting them. This is a concerning trend in cybersecurity, as many organizations have implemented stronger password security protocols and multifactor authentication (MFA), making traditional credential theft more difficult.
The shift towards targeting session artifacts has been described by experts as complicating incident response efforts. Simply resetting a password may not be enough to cut off an attacker who already has a valid session or refresh token. In Anthropic’s case, the infostealers harvested Claude sessions, likely along with other sensitive information such as login cookies and saved passwords for other apps.
The impact of these attacks is significant, as users reported that their Google Chrome credentials, including cookies and session IDs, were stolen, allowing the attackers to bypass all two-factor authentication security measures. Anthropic has taken steps to mitigate the damage by signing affected users out of their Claude accounts and removing their saved payment methods. In cases where unauthorized charges were made using compromised payment cards, the company has refunded the amounts.
To protect against similar attacks, it’s essential for users to take proactive steps. After removing infostealer malware from your system, you should secure any email account associated with your Claude account by setting a new password, signing out of other devices, and enabling two-factor authentication. This will prevent attackers from reusing stolen session information.
The Anthropic incident serves as a reminder that cybersecurity threats are constantly evolving, and organizations must stay vigilant in protecting their users’ sensitive information. By understanding the tactics used by threat actors and taking proactive measures to secure your accounts, you can reduce the risk of falling victim to these sophisticated attacks.
Source: Dark Reading — 2026-08-31