Claude infostealer session-hijack campaign
Campaign
Summary
Hide ▲
Show ▼
A campaign is abusing stolen Claude sessions to enter affected accounts, drain usage limits, and force protective sign-outs. Anthropic says the session material came from infostealer malware on users' computers, including Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer (AMOS) on some macOS devices. The company has signed out compromised sessions, removed saved payment methods, and refunded unauthorized charges. Users whose limits refilled and then drained without active use were told that account misuse was the likely cause.
Related Happenings
Infostealer malware hijacks Claude sessions
Malware Activity
H score36
First: 30.08.2026 17:30
Last: 30.08.2026 17:30
Sources 1
About this happening:
Anthropic warned that infostealer malware is stealing Claude login sessions from infected PCs, letting attackers reuse them for account access and consumption of usage...
Infostealer malware hijacks Claude sessions
Malware ActivityAbout this happening: Anthropic warned that infostealer malware is stealing Claude login sessions from infected PCs, letting attackers reuse them for account access and consumption of usage...
Mexico’s tax authority hit by network compromise
Incident
H score78
First: 06.03.2026 15:37
Last: 06.03.2026 15:37
Sources 1
About this happening:
A prolonged intrusion hit Mexico’s tax authority and at least eight other government organizations, putting 195 million identities and tax records at risk. The att...
Mexico’s tax authority hit by network compromise
IncidentAbout this happening: A prolonged intrusion hit Mexico’s tax authority and at least eight other government organizations, putting 195 million identities and tax records at risk. The att...
Timeline
-
31.08.2026 15:11 2 articles · 1h ago
Anthropic warns Claude users after infostealer malware hijacks sessions
Initial DisclosureAnthropic warned some Claude users that infostealer malware on their Windows computers and a small number of macOS devices stole browser cookies and passwords, allowing a threat actor to reuse Claude login sessions and drain usage limits. The company said it detected the activity, signed out compromised sessions, removed saved payment methods from affected accounts, and refunded unauthorized Claude charges.
Show sources
- Anthropic Warns Claude Users of Infostealer Malware Infections — www.securityweek.com — 31.08.2026 15:11
- Anthropic Warns Claude Users of Infostealer Malware Infections — www.securityweek.com — 31.08.2026 15:11