Your Password Was Fine. The Stolen Claude Session Still Drained the Account
Anthropic has warned affected users that infostealer malware is hijacking active Claude sessions and draining paid usage. The attackers do not need to defeat the victim’s password or multi-factor authentication if they can steal a browser session that has already passed those checks.
The warning, reported by BleepingComputer, names Windows stealers including Vidar, LummaC2, StealC, RedLine and Acreed, plus Atomic macOS Stealer. Anthropic sent the notice privately to affected users rather than publishing a public incident advisory.
A session is temporary authentication with real value
After a successful login, a service gives the browser a session token so the user does not need to enter a password on every page. Malware running on the computer can steal that token and present it from another location.
The server may then see an already authenticated session rather than a new login. A strong password and two-factor authentication still protect the initial sign-in, but they cannot retroactively protect a token copied from an infected device.
Anthropic’s support documentation says web sessions last 28 days by default and can be refreshed through activity. That creates a useful window for legitimate users and a potentially valuable asset for a stealer operator.
The immediate objective was paid usage
According to the warning quoted by BleepingComputer, attackers accessed victims’ Claude accounts and consumed available usage. Anthropic said it was signing affected users out, removing payment methods and refunding identified unauthorised charges.
Usage theft may look less serious than a data breach, but account access can expose conversation history, uploaded material and connected workflows depending on how the service is used. Organisations should assess the data and integrations available to the hijacked account, not only the financial charge.
Logging out is necessary, but not sufficient
Anthropic provides controls to review active sessions and sign out everywhere. That invalidates existing sessions and is the right immediate containment step.
It does not remove the malware. If the user signs in again on the same infected computer, the next session can be stolen too. The endpoint must be isolated, investigated and cleaned or rebuilt before the account is trusted again.
What affected users should do
- Use Anthropic’s active-session page and sign out sessions that are not recognised.
- Sign out of all Claude sessions after isolating the suspected device.
- Run an endpoint investigation for infostealer persistence, stolen browser data and secondary credential theft.
- Change the Claude password from a known-clean device and review multi-factor authentication settings.
- Review conversation history, uploaded files, connected tools and usage records for unauthorised access.
- Remove saved payment methods where appropriate and confirm refunds through official support channels.
- Rotate other credentials stored in the affected browser, including email, cloud and developer-service sessions.
- Do not treat a password reset as proof that the endpoint is clean.
The enterprise lesson
Infostealers have made session security an identity problem. Security teams need telemetry for impossible session movement, abrupt usage changes and new activity that does not match the endpoint or user.
Browser sessions should also be included in incident-response playbooks. A stolen cookie can provide access to multiple services even when no plaintext password appears in the malware logs.
The BlackTree view
The password was not the failed control. The trusted session was copied after the password had done its job.
That changes the recovery sequence. Sign out the sessions, investigate the device, rotate related credentials and review what the account could reach. If the malware remains, the next clean login simply creates another token worth stealing.
Sources
- BleepingComputer: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage, published 30 August 2026 at 10:30. The page does not display a timezone. The company warning was sent privately, so the report is the strongest public copy available.
- Anthropic support: managing active sessions, accessed 31 August 2026.
- Anthropic support: signing out of all active sessions, accessed 31 August 2026.


