Anthropic has notified some Claude users that infostealer malware running on their computers stole active Claude login sessions, which third parties then used to access the accounts and consume paid usage. The company described the activity in an email sent to an affected user, who published it on Reddit. BleepingComputer reported the warning on 30 August 2026. The stolen object is a session, not a password: the malware harvested an already-authenticated browser state, so no credential compromise was involved.
The email reads: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Two details sit in that sentence. The tooling is described as common, commodity infostealer software rather than anything built for Claude, and the stated objective is consumption of usage, which on a paid account converts directly into the attacker's benefit at the victim's cost.
XenoSpectrum's analysis of the incident notes that infostealers broadly harvest passwords and browser data from an infected device, and in this case also extracted already-authenticated Claude sessions alongside everything else. That suggests the AI service was an incidental target collected in bulk rather than a targeted campaign against Anthropic. The practical symptom for a victim is usage draining without any activity on their part, a pattern the report says this kind of abuse could explain.
Anthropic's response, reported by BleepingComputer and corroborated by Gigazine on 31 August, had three parts: the company signed affected users out of Claude, deleted their saved payment methods, and refunded charges it identified as unauthorized. Gigazine characterized the targets as users suspected of malware infection, which indicates the measures were applied on suspicion rather than after individual forensic verification of each machine.
Each measure addresses a distinct exposure. Forced logout invalidates the stolen session tokens, the logic being that when the authentication artifact itself is the stolen asset, a password change alone would leave an active session valid. Removing saved payment methods prevents the attacker, or an automated script holding the session, from re-attaching billing and continuing to drain usage. Refunds return the money but do not answer how unauthorized consumption went undetected at the point it occurred.
Search Engine Journal's account of the same email confirms the identical package: sign-out and payment-method removal for users whose computers were compromised. The structure of the response treats the user's device as the compromised perimeter and the account as the asset to contain. Anthropic did not state in the email how it identified which accounts to act on, a gap that carries weight given the measures also disrupt legitimate sessions for anyone flagged.
What Anthropic has not disclosed: the number of affected users, the timeframe over which the session theft occurred, and how the activity was detected. XenoSpectrum flags all three as absent from the company's communication, and the notification email itself contains no scope figures. Without a count, the incident cannot be sized against other infostealer-driven account abuse; without a timeframe, it cannot be tied to any specific malware distribution wave.
The detection question is the most consequential of the three. The existence of notification emails shows Anthropic identified affected accounts through some internal process, but the company has not said whether that process was usage-anomaly monitoring, security tooling, or reports from users. Each implies a different detection capability, and each leaves a different blind spot. The open question is whether consumption anomalies alone would surface an attacker who deliberately throttled usage to stay below thresholds.
The incident documents a shift in what infostealer harvests are worth. A Claude session is not only an account; it is a metered resource with direct monetary value, which makes AI sessions a rational target for the same commodity malware that already collects banking and email cookies. Whether Anthropic publishes fuller incident detail, and whether other AI providers acknowledge comparable session theft, will indicate whether this was isolated abuse or a category.
Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.
The AI news that matters — in your inbox by 07:30 CET. Free, no spam.