Stolen Claude sessions: Anthropic signs accounts out and removes saved cards

Infostealer malware on users' computers copied Claude sessions; when a bad actor started using them, Anthropic signed the sessions out. The notice names six malware families; what to do is in the story.

Paylaş
Stolen Claude sessions: Anthropic signs accounts out and removes saved cards

Anthropic has signed a subset of Claude users out of their sessions and removed saved payment methods from their accounts. The cause is not a flaw in Claude: infostealer malware on users' own computers copied Claude sessions along with browser login cookies, and when a bad actor began working through the stolen sessions to access accounts and consume usage, Anthropic's systems caught the activity.

According to the notice sent to users, the families identified in the campaign are Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs. Anthropic says there is no indication the malware is related to Claude or installed through it - these are general-purpose stealers that arrive with unofficial downloads and malicious apps - and phones and tablets do not appear to be involved.

The measures taken: all affected sessions were signed out (which also invalidates the stolen copies), and saved cards were removed against unauthorised charges. If your usage limits looked like they refilled and then drained while you were away, the notice says this was the likely cause.

What to do

One. Log back in and re-add your card in settings. Two. Scan your device with an up-to-date security tool; the stealer collects every password in the browser, not just Claude - change the critical ones. Three. Download Claude and Claude Code only from official addresses: fake Anthropic sites have been distributing fileless infostealers disguised as Claude Code in recent weeks.

Source: Anthropic's notice to users · Hackread · TechRadar