Find notable cyber news and cases, enriched with sources, timelines, and signals.

Claude infostealer session-hijack campaign

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

A campaign is abusing stolen Claude sessions to enter affected accounts, drain usage limits, and force protective sign-outs. Anthropic says the session material came from infostealer malware on users' computers, including Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer (AMOS) on some macOS devices. The company has signed out compromised sessions, removed saved payment methods, and refunded unauthorized charges. Users whose limits refilled and then drained without active use were told that account misuse was the likely cause.

Related Happenings

Infostealer malware hijacks Claude sessions

Malware Activity
H score36 First: 30.08.2026 17:30 Last: 30.08.2026 17:30 Sources 1

About this happening: Anthropic warned that infostealer malware is stealing Claude login sessions from infected PCs, letting attackers reuse them for account access and consumption of usage...

Mexico’s tax authority hit by network compromise

Incident
H score78 First: 06.03.2026 15:37 Last: 06.03.2026 15:37 Sources 1

About this happening: A prolonged intrusion hit Mexico’s tax authority and at least eight other government organizations, putting 195 million identities and tax records at risk. The att...

Timeline

  1. 31.08.2026 15:11 2 articles · 1h ago

    Anthropic warns Claude users after infostealer malware hijacks sessions

    Initial Disclosure

    Anthropic warned some Claude users that infostealer malware on their Windows computers and a small number of macOS devices stole browser cookies and passwords, allowing a threat actor to reuse Claude login sessions and drain usage limits. The company said it detected the activity, signed out compromised sessions, removed saved payment methods from affected accounts, and refunded unauthorized Claude charges.

    Show sources