Anthropic Users Hit by Infostealer Attacks, Session Thefts

A sophisticated threat actor has been stealing login sessions and accessing sensitive information from a large number of users who interact with Anthropic’s AI platform, Claude. The attacks came to light when users began receiving email notifications that they had been signed out of their accounts, and further investigation revealed that the culprit was a type of malware known as an infostealer.

The infostealers in question are able to collect session information and access user accounts without needing to guess or steal passwords. This is particularly concerning because it allows attackers to bypass multifactor authentication (MFA) protocols and gain unauthorized access to sensitive data. According to Anthropic, the threat actor used a variety of infostealers, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows systems, as well as Atomic Stealer (AMOS) on a small number of Macs.

The attacks are a prime example of how cyber attackers have shifted their focus from stealing passwords to targeting session cookies and authentication tokens. With many organizations implementing stronger password security protocols and MFA, traditional credential theft has become increasingly difficult for attackers to execute. As a result, they have begun targeting session artifacts, which can be used to hijack already-authenticated sessions and bypass MFA altogether.

The Anthropic incident highlights the importance of staying vigilant in terms of endpoint security and protecting against infostealer malware. Infostealers are designed to harvest sensitive information from compromised systems, often without the user’s knowledge or consent. In this case, the attackers were able to steal Claude login sessions, likely along with other sensitive data such as login cookies, saved passwords, and credentials for other apps.

The consequences of these attacks can be severe, particularly when it comes to sensitive information like authentication tokens. As one affected user noted on Reddit, the hacker was able to bypass all two-factor authentication security measures by stealing their Google Chrome credentials, including cookies and session IDs. To mitigate this risk, Anthropic has taken steps to protect its users, signing them out of their accounts and removing saved payment information associated with compromised accounts.

However, the notification from Anthropic also emphasized that simply signing users out of their accounts does not eliminate the threat entirely. In order to prevent further attacks, affected users must remove the infostealer malware from their systems and take steps to secure their email accounts by setting new passwords, signing out of other devices, and enabling two-factor authentication.

The incident serves as a stark reminder of the importance of staying ahead of emerging threats in the cybersecurity landscape. As attackers continue to evolve and adapt their tactics, it’s essential for individuals and organizations to remain vigilant and take proactive steps to protect themselves against these types of attacks. By being aware of the risks and taking necessary precautions, we can reduce our exposure to this type of threat and stay one step ahead of the bad guys.


Source: Dark Reading — 2026-08-31