A sophisticated malware campaign targeting users of Anthropic’s Claude AI platform has compromised thousands of accounts, allowing attackers to hijack login sessions and run up unauthorized charges. In an email notification sent to affected customers, Anthropic revealed that infostealer malware had infiltrated computers running Windows and macOS, stealing sensitive information such as saved passwords, browser cookies, and local application credentials.
The malware, identified as Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer (AMOS), is a general-purpose threat that typically arrives on devices via unofficial downloads or malicious apps. Once installed, it quietly copies sensitive data, which is then harvested by the attackers. In some cases, users reported seeing their usage limits refill unexpectedly only to be drained again without any activity, indicating that the stolen login sessions were being used to access their accounts.
Anthropic detected the suspicious activity and took swift action to protect its users. The company signed out compromised sessions, removed saved payment methods from affected accounts as a precaution, and refunded any unauthorized charges. Affected users have been advised to ensure all malware is removed from their computers before re-adding a payment method to prevent further unauthorized transactions.
This incident highlights the importance of robust security measures in protecting sensitive information and preventing malicious activity. While Anthropic’s prompt response has mitigated the damage, it serves as a reminder that even with advanced AI-powered tools like Claude, user vigilance and adherence to best security practices are essential in preventing such attacks.
Users of the Claude platform should remain vigilant and take steps to protect their accounts from similar threats. This includes regularly updating software and apps, using strong passwords and enabling two-factor authentication, as well as being cautious when downloading unofficial apps or files that may be malicious. Additionally, users should monitor their account activity closely for any suspicious behavior, such as unexpected login sessions or charges. By taking proactive steps to secure their accounts and devices, users can minimize the risk of falling victim to similar attacks in the future.
Source: SecurityWeek — 2026-08-31