Anthropic is signing people out of Claude. The malware was never Claude's problem — the session was.
TL;DR: Over 30–31 August 2026 Anthropic began notifying Claude users that commodity infostealer malware on their own computers stole active Claude login sessions, which a bad actor replayed to consume their paid usage. Named families: Vidar, LummaC2, StealC, RedLine, Acreed on Windows and Atomic Stealer on macOS. The tell was usage limits that appeared to refill and then drained while the account owner was idle. Anthropic is signing the sessions out, removing saved payment methods, and refunding charges it identifies as unauthorised, and states plainly that the malware is not related to Claude, not installed through Claude, and not caused by anything the user did with Claude — all of which the evidence supports. No Anthropic system was breached. No affected-user count has been published. Why it still matters: what was stolen was not a password but an already-authenticated session, which walks past 2FA and SSO by design — there is no second prompt to fail. And the reason Claude accounts became worth stealing is new: an AI subscription is now a metered, resellable commodity. For you: a stolen Claude cookie means that whole machine is compromised, sign-out does not remove malware, and “we have SSO” is an incomplete answer to how your AI seats are protected.
What happened
Anthropic began contacting affected Claude users over 30–31 August 2026 with an unusually direct notice:
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.”
Three actions accompanied it. Anthropic signed the affected sessions out, removed saved payment methods from those accounts, and is refunding charges it identifies as unauthorised.
The company was equally direct about what this is not. It has no reason to believe the malware is related to Claude, was installed through Claude, or was caused by anything the user did with Claude. No Anthropic system was breached. The infection is on the user’s own computer, and at least one identified case traced back to a pirated software download.
The malware families named are all well-known commodity stealers: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a limited number of macOS systems. These are not Claude-specific tools. They sweep browser cookies, saved passwords and local credentials from whatever machine they land on, and they have been doing so for years.
Anthropic also published the detail that makes the notice more than housekeeping:
“Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware. If it’s still on your computer, your next login session could be stolen the same way.”
The behavioural fingerprint users reported: usage limits that looked like they refilled and then drained while nobody was using the account. Anthropic has not published how many accounts were affected.
The part that generalises: 2FA never applied
The reflex on reading an account-compromise story is to check whether multi-factor authentication was enabled. Here that question has no purchase, and understanding why is the whole value of the incident.
Two-factor authentication protects the act of logging in. Nothing logged in.
When you authenticate to a web application, the server hands your browser a session token — a cookie — that every subsequent request presents as proof that the login already happened. From that moment, the token is the credential. An infostealer that copies it off disk can replay it from any machine on earth, and the service sees a session that has already satisfied every check you configured: password, second factor, single sign-on, device trust. There is no second prompt to fail, because there is nothing left to prove.
This is why “we have SSO and MFA on our AI tools” is an incomplete answer to how those seats are protected. Those controls govern the door. What was taken was a key already turned in the lock.
It is also why the correct response to an infostealer indicator is never “change the Claude password.” The stealer that took a Claude cookie took everything else readable on that filesystem in the same pass — saved browser passwords, other sessions, local credential files. Anthropic’s sign-out closes one replayed session on one service. It does nothing about the machine.
Why Claude accounts became worth stealing
The more interesting question is not how the sessions were taken. Commodity stealers have harvested cookies indiscriminately for a decade. The question is why AI subscriptions are now among the things worth doing something with.
The answer is that AI seats have become a metered, resellable commodity in a way that ordinary SaaS logins never were. A stolen Netflix session gets somebody free television. A stolen Claude session gets somebody a quantity of frontier-model inference with a market price, obtainable in bulk, consumable immediately, and reachable through an interface that requires no infrastructure to exploit. The 2026 shift toward high-allowance subscription tiers and always-on agent billing made each individual account worth materially more than it was two years ago.
That reframes something buyers have not generally internalised. Your AI subscription is no longer a productivity expense that happens to have a login. It is a credential class with a resale value, and it should inherit the handling you already give things with resale value.
It also explains the shape of the attack. Nobody wrote Claude-aware malware. Generic stealers already had the cookies; someone worked out what the Claude ones were worth. That is a threat-landscape change, not a vendor hygiene failure, and it applies identically to ChatGPT, Gemini and Copilot sessions sitting in the same browser profile.
This is the second Claude-branded lure this summer
The incident lands with prior context that is worth keeping straight, because the two are frequently conflated and only one of them is this week’s news.
In July 2026, researchers at Huntress documented a campaign they named FakeAgent. Victims searching Bing for the Claude desktop app were served a sponsored advertisement pointing at the legitimate claude.ai domain — where the attackers had hosted a malicious Claude Artifact, borrowing Anthropic’s own certificate and reputation. The Artifact was downloaded roughly 7,100 times before Anthropic removed it, and directed visitors to a fake ClaudeDesktop.exe: a renamed, signed JetBrains helper that sideloaded a tampered library to deploy SectopRAT, with command-and-control addresses read from Ethereum contracts. At least 29 organisations were compromised across 21–22 July.
That was a separate campaign, six weeks earlier, and there is no published evidence linking it to the session thefts announced this week. What the pair demonstrate together is a trend worth naming: AI vendors’ own domains and brands have become high-trust distribution surfaces, and a user-hosted artifact platform on a trusted domain is a genuinely awkward thing to secure. The generic warning to “check the URL” fails when the URL is correct.
Where this sits against the year’s other AI security stories
2026 has produced a run of AI security incidents with a common structure: the model was fine, and the plumbing around it was the exposure. The Hugging Face production compromise following a sandbox escape was an isolation-boundary failure, not a model failure. Anthropic’s own move toward self-hosted sandboxes and MCP tunnels was an attempt to shrink exactly that surface. This week’s story is the same shape at the consumer end: nothing about Claude’s behaviour mattered, and everything about the credential wrapper around it did.
It arrives, pointedly, in the same month that the EU AI Office issued its first formal requests for information to frontier providers — covering model security, independent external evaluation and post-market monitoring — the enforcement follow-through to the transparency obligations that became applicable on 2 August. The regulatory attention is aimed at model-level risk. The incident that actually cost users money this week was a stolen cookie. Both are real; only one of them has a compliance regime pointed at it.
The trajectory also raises the stakes going forward. As assistants get wired deeper into the systems of record — Claude becoming the default model across Slack and Agentforce is the clearest example — the value of a hijacked session stops being measured in consumed tokens and starts being measured in reachable data. A replayed session against a chat assistant burns your allowance. A replayed session against an assistant with governed actions into your CRM is a different category of event entirely.
What to do
- Treat the endpoint as compromised, not the account. If you received Anthropic’s notice or saw usage drain while idle, the machine is the incident. Run a full scan, rotate the linked email password with a second factor enabled, revoke active sessions across every service, and replace every credential that was stored in that browser. Signing back into Claude on an uncleaned machine simply donates a fresh session.
- Re-add payment methods deliberately. Anthropic removed saved payment methods from affected accounts. Restore them once the device is clean, not before, and check the interim statements for charges the refund pass may have missed.
- Audit your automated AI credentials. The consumer surface is what got hit; the developer surface is the one that would hurt. Inventory API keys in local config, tokens on build agents, and OAuth grants held by Claude Code and comparable agentic coding tools. Assume anything readable on a developer laptop was readable by a stealer.
- Add session controls to your vendor review. Session lifetime, admin-initiated organisation-wide revocation, usage-anomaly detection, and proactive notify-and-refund policy. These are absent from nearly every AI tool comparison — including the chatbot and Claude vs ChatGPT breakdowns on this site — and they belong in the next procurement conversation you have.
- Point someone at AI billing anomalies. The detection signal in this incident was consumption. Finance saw it before security could have. Decide now who owns that alert.
- Download desktop AI clients from the vendor’s documented link only. Never from a search advertisement, even one whose destination domain looks correct. FakeAgent is the standing proof that the domain check is not sufficient.
Honest caveats
No affected-user count has been published, so the scale of this is genuinely unknown. It could be a few hundred accounts or a great many.
Reporting dates differ by a day across outlets — some place Anthropic’s notice on 30 August, others on 31 August. The substance is consistent across all of them; the exact notification timestamp is not.
The scope is web login sessions. No published source extends this incident to Claude Code, API keys or CLI credentials, and this article does not claim otherwise. The point made above is that the mechanism does not respect that boundary, which is a reason to audit rather than a report of harm.
Anthropic’s account is the primary source for its own conduct. The sign-outs, payment-method removals and refunds are the company’s description of what it did, corroborated by user-received notices reported across security outlets, not independently audited.
No product testing informs any of this. This site runs no software and evaluates no tools directly; the analysis above is drawn from the cited reporting.
Frequently asked questions
How do I know whether my Claude account was one of the affected ones?
There are two signals and one of them is unreliable, so check both. The direct signal is a notification from Anthropic: affected users are being signed out of Claude and told that their saved payment method has been removed, and Anthropic is refunding charges it identifies as unauthorised. If you got that message, you are in scope and the malware is on a device you use, not on Anthropic's systems. The behavioural signal is the one Anthropic itself described as the tell: usage limits that appeared to refill and then drained while you were not using Claude. If you noticed a Pro or Max allowance evaporating overnight, or hitting a cap on a day you barely opened the app, that is the fingerprint of somebody replaying your session. The unreliable part is the absence of both signals. Anthropic has not published a number of affected accounts, and an infostealer that took your Claude cookie almost certainly also took your saved browser passwords and every other session on that machine. So a quiet Claude account is not evidence of a clean computer. If you have downloaded pirated or cracked software, installed a desktop app from a search advertisement rather than the vendor's own domain, or share a machine with somebody who might have, run a full endpoint scan regardless of what your usage graph looks like.
I have two-factor authentication turned on. Why did that not stop it?
Because two-factor authentication protects the act of logging in, and nothing was logged in. This is the single most important technical detail in the story and it generalises far beyond Claude. When you authenticate to a web application, the server issues a session token — typically a cookie — that your browser presents on every subsequent request as proof that the login already happened. That token is the credential from that point on. An infostealer that copies it off your disk can replay it from anywhere and the service sees a session that already passed every check: password, second factor, single sign-on, device trust. There is no second prompt to fail, because from the server's perspective there is nothing left to prove. This is why the security industry has spent several years moving toward token binding and continuous session validation rather than treating strong login as the finish line, and it is why 'we have SSO and MFA' is an incomplete answer to 'how are our AI seats protected'. The controls you bought govern the door. What was stolen was a key already turned in the lock.
Anthropic says the malware has nothing to do with Claude. Is that a deflection?
No, and treating it as one would cost you the actual lesson. Anthropic's position is that it has no reason to believe the malware is related to Claude, was installed through Claude, or came from anything a user did with Claude, and the evidence supports that. The named families — Vidar, LummaC2, StealC, RedLine and Acreed on Windows, Atomic Stealer on macOS — are long-running commodity infostealers that indiscriminately sweep browser cookies, saved passwords and local credentials from infected machines. They are not Claude-aware tooling. At least one identified compromise traced back to a pirated software download. No Anthropic system was breached. What Anthropic is responsible for here is the response, and signing sessions out, removing stored payment methods and refunding unauthorised charges is a proportionate one. The reason to keep paying attention is not vendor fault. It is that these generic stealers have started monetising a credential class that did not exist five years ago, which means the criminal ecosystem has now priced your AI subscription. That is a change in the threat landscape, not a change in Anthropic's hygiene.
What should a team actually do differently on Monday?
Four things, in descending order of how much they matter and ascending order of how much work they are. First, treat any endpoint that shows infostealer indicators as fully compromised rather than selectively cleaned: rotate the email password with a second factor enabled, revoke every active session on every service, and replace anything stored in that browser, because the Claude cookie was never the only thing taken. Second, find your automated AI credentials, which are the ones nobody thinks of during a consumer-flavoured incident — API keys checked into local config, tokens on build agents, OAuth grants held by agent frameworks and CLIs — and decide which of them a person with disk access could have lifted. Third, add one question to your AI vendor review that almost nobody asks: does this vendor let an administrator revoke all sessions for a user, organisation-wide, without a support ticket, and how long do its sessions live? You will find the answers are inconsistent across the tools you already pay for. Fourth, decide who watches billing anomalies on AI spend. The tell in this incident was consumption, and consumption is the signal your finance dashboard sees before your security team does.
Does this affect Claude Code, API keys or agent tooling as well as the web app?
The reported incident is specifically about web login sessions, and it would be wrong to claim more than that. The published accounts describe stolen browser session cookies replayed against Claude accounts to consume usage, and none of the coverage extends the finding to Claude Code, API keys or CLI credentials. What is reasonable to say is that the mechanism does not respect that boundary even if this particular campaign did. Commodity infostealers take whatever is readable on the filesystem, and modern developer machines hold a great deal that qualifies: long-lived API keys in dotfiles and environment files, OAuth refresh tokens cached by command-line tools, and credentials for the agent frameworks that a growing share of teams now leave running against real repositories. An agent credential is a materially worse thing to lose than a chat session, because it can act rather than merely consume — the same asymmetry that made the sandbox-escape incidents earlier this year serious. So the honest framing is that this incident proves the consumer surface is being monetised, and it should prompt you to audit the developer surface before somebody proves that one too.
Should this change which AI vendor we buy from?
Not on its own, because there is no comparative evidence here and the failure was not the vendor's. Nothing in this incident suggests Claude accounts are less well protected than the alternatives; the stealers involved take whatever cookies they find, and a ChatGPT, Gemini or Copilot session on the same infected machine would have been just as replayable. Choosing a different chat assistant on the basis of this story would be substituting one identical exposure for another. What it should change is a line item in how you evaluate all of them. Session lifetime, administrator-initiated session revocation, anomaly detection on usage spikes, and whether the vendor will proactively notify and refund are now legitimate procurement criteria alongside model quality and price, and they are currently invisible in every comparison table including the ones on this site. Anthropic's conduct in this incident — proactive notification, sign-out, payment-method removal, refunds — is a reasonable benchmark to hold the others to. Ask your incumbent vendors what they would have done, and note carefully which ones cannot answer.
Sources
- BleepingComputer — Anthropic warns infostealer malware is hijacking Claude sessions to drain usage (30 August 2026)
- CyberSecurityNews — Hackers steal Claude login sessions with infostealer malware to hijack accounts
- Search Engine Journal — Anthropic warns hackers are stealing Claude sessions to hijack accounts
- GBHackers — Hackers use infostealer malware to steal Claude session cookies and hijack accounts
- News4Hackers — Anthropic warns of infostealer malware hijacking Claude sessions to drain usage
- Huntress — Inside FakeAgent: how a Claude Desktop malvertising campaign hit 29 organisations with SectopRAT (July 2026)
- BleepingComputer — Fake Claude app promoted by Bing ads pushes SectopRAT malware (July 2026)
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.