Anthropic Logs Out Claude Users After Infostealer Wave

Anthropic has begun forcibly logging Claude users out of their accounts and stripping stored payment methods after detecting widespread abuse driven by commodity infostealer malware hijacking live browser sessions.[1][5][12][13] The company is also refunding confirmed unauthorized charges and notifying affected customers as part of an ongoing incident response effort.[5][13] Anthropic emphasizes that the activity reflects endpoint compromises on user machines rather than a breach or vulnerability in the Claude service itself.[1][5][13]

According to notices shared with customers and later reported by security outlets, attackers are using families such as Vidar, LummaC2, StealC, RedLine, Acreed and the macOS-focused Atomic Stealer (AMOS) to siphon browser passwords, login cookies and other credentials from infected systems.[1][5][13] Once the malware has exfiltrated active Claude session cookies, adversaries can access accounts and consume paid usage without ever stealing the underlying password or bypassing multi-factor authentication.[1][5] Anthropic has stressed in its messaging that Claude itself is not the delivery mechanism for these threats and that infections stem from malicious downloads or applications on compromised endpoints.[1][5]

To blunt the abuse, Anthropic is revoking identified compromised sessions, signing users out across devices and deleting saved payment cards associated with suspicious activity.[1][5][12][13] The company is advising organizations to treat unexpected spikes in Claude usage, strange prompt histories or unfamiliar projects as possible signs of an underlying infostealer infection rather than mere account misuse.[5][13] In guidance circulated to impacted users, Anthropic urges them to change passwords, review active logins, enable multi-factor authentication where available and fully clean infected machines before signing back in.[1][5][13]

This incident does not appear tied to any new Claude or Claude Code vulnerability and has not been assigned a CVE, underscoring that traditional endpoint malware remains a primary risk vector even for cloud AI services.[1][5][13] It stands in contrast to previously disclosed flaws in Anthropic’s Claude Code tooling, such as information disclosure bug CVE-2026-21852 and workspace-trust bypass CVE-2026-33068, which allowed malicious repositories to exfiltrate data or skip consent dialogs before being patched earlier this year.[2][3][4][7][14][15] In the current case, infostealers are simply piggybacking on legitimate sessions, exploiting the fact that many web applications rely on long-lived cookies that can be replayed from another machine once stolen.[1][5][8]

Threat researchers have warned throughout 2026 that infostealers increasingly target developers and AI users by impersonating tools like Claude Code or bundling malicious installers that quietly harvest credentials, crypto wallets and browser sessions behind the scenes.[8] For defenders, that makes telemetry from endpoint detection and response tools, browser security controls and application logs essential to correlating unusual Claude activity with specific compromised hosts.[5][8][13] Organizations using Claude at scale should consider tightening conditional access policies, shortening session lifetimes, and monitoring for sign-ins from unexpected locations or autonomous scripts that resemble automated abuse rather than human usage.[5][8]

The incident is another reminder that AI accounts are now high-value targets and that multi-factor authentication alone cannot fully protect them when attackers can simply lift a victim’s authenticated session from an infected device.[1][5][8] Anthropic’s move to proactively log users out, scrub stored payment data and reimburse fraud offers short-term relief, but durable protection will depend on organizations hardening endpoints, clamping down on illicit software downloads and raising user awareness about the risks posed by modern infostealers.[1][5][8][13]

References

  1. Anthropic warns infostealer malware is draining Claude …
  2. CVE-2026-33068: Anthropic Claude Code Auth Bypass Flaw
  3. Claude Code Flaws Allow Remote Code Execution and …
  4. CVE-2026-39861: Anthropic Claude Code RCE Vulnerability
  5. Infostealers Hijack Claude Browser Sessions to Abuse AI Usage
  6. CVE-2026-21852: Claude Code Information Disclosure Flaw
  7. Kaspersky discovers infostealers mimicking Claude Code …
  8. International Cyber Digest on X: “‼️BREAKING
  9. Intelligence – Mallory.ai
  10. Anthropic’s Claude Code had a workspace trust bypass (CVE-2026-33068). Not a prompt injection or AI attack. A configuration loading order bug. Fixed in 2.1.53.
  11. CVE-2026-35603: Claude Code Privilege Escalation Flaw

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply