Claude Users Hit by Infostealer Malware, Risking Account Takeovers and Unauthorized Charges
Anthropic, the AI giant behind the popular Claude AI platform, has issued a warning to some of its users that their accounts have been compromised due to infostealer malware infections on their computers. The company detected the malicious activity, took steps to protect affected customers, and alerted those whose accounts may be at risk.
The issue affects users who have installed infostealer malware such as Vidar, Lumma, StealC, RedLine, and Acreed on Windows devices, as well as a small number of macOS machines with Atomic Stealer (AMOS). These types of malware are designed to quietly siphon sensitive information from infected computers, including saved passwords, browser login cookies, and credentials for other local applications. In some cases, the stolen data has been used by attackers to hijack login sessions and run up unauthorized charges on affected accounts.
The situation highlights the importance of cybersecurity in the AI era, where even seemingly secure platforms can be vulnerable to malicious activity. Anthropic emphasized that the malware is not specific to Claude itself but rather a general-purpose threat that often arrives via unofficial downloads or malicious apps. Users who have fallen victim to this campaign are being advised to ensure that all malware has been removed from their computers before re-adding payment methods to their accounts.
In response to the incident, Anthropic signed out affected sessions and warned users that they may be signed out again if further signs of account misuse are detected. The company also removed saved payment methods from compromised accounts to prevent unauthorized charges and refunded any Claude charges it identified as being unauthorized. Users who have been affected by this campaign are encouraged to take immediate action to protect their accounts.
The incident serves as a reminder for users to stay vigilant when it comes to cybersecurity, especially in the context of AI-powered platforms that often rely on user data. To minimize risks, Anthropic is urging its customers to only re-add payment methods after thoroughly checking their computers for malware and ensuring that all necessary security measures are in place.
Ultimately, this incident underscores the importance of robust cybersecurity practices in today’s digital landscape. As we increasingly rely on AI-powered services, it’s essential to prioritize security and take proactive steps to protect ourselves from emerging threats like infostealer malware. By staying informed and taking action to safeguard our accounts, we can mitigate the risks associated with these types of malicious activity.
Source: SecurityWeek — 2026-08-31