Key takeaways
- Anthropic has warned Claude users about an infostealer campaign aimed at stealing login sessions.
- Cybercriminals are increasingly targeting AI platform credentials and usage credits.
- Affected users have been signed out, their payment details removed, and refunds are being issued.
- Users must run a malware scan and remove risky software before re-entering payment information.
Anthropic has started alerting Claude users about a campaign that uses infostealer malware to hijack their accounts and drain paid usage credits. The company says affected users have been signed out and their saved payment information removed. Refunds are being issued for unauthorized charges, but security experts say the real fix begins on the user's own device.
An infostealer is a type of malicious software designed to quietly collect credentials, cookies, payment card data, autofill entries, and session tokens from an infected system. Unlike ransomware, which makes itself known, infostealers work silently in the background. They bundle the stolen data into logs and send it to an attacker, who can then use it for account takeover, financial fraud, or resale on cybercrime markets. For years, the main targets were webmail accounts, social media profiles, bank details, and cryptocurrency wallets. Now AI platforms have become part of that target set.
What happened
Anthropic said it became aware of a bad actor using common infostealer malware to steal Claude login sessions from people's computers. Those stolen sessions were then used to access Claude accounts and consume the victims' usage allowances. Because many Claude accounts are connected to a payment method, the abuse could also result in unexpected charges. Anthropic has responded by signing affected users out of their accounts, wiping stored payment information, and refunding unauthorized usage costs.
The warning explains that the attacker did not necessarily need passwords. A saved login session is a digital pass that lets a user remain authenticated without entering credentials again. When an infostealer copies that session data from a browser, the attacker can import it into their own browser and access the account as if they were the legitimate user. This can bypass some of the protections that normally prevent account takeover, especially if multi-factor authentication is tied to a cookie or session token that the browser has already whitelisted.
According to the alert, the stolen sessions have been used to drain usage credits. Some victims may have noticed that their usage limits appeared to refill and then empty while they were not actively using Claude. That pattern is listed as one of the clearest signs that an account had been hijacked.
How users became infected
The campaign is targeting Windows and macOS PCs. Windows users have encountered infostealer families such as Vidar, Lumma, StealC, and RedLine, while a small number of Mac infections have been linked to Atomic Stealer. There is currently no evidence that phones or tablets are affected.
Anthropic has said it has no reason to believe the malware is related to Claude, was installed through Claude, or was caused by anything users did inside the AI assistant. In one example shared by an affected user, the likely source of the infection was a cracked game downloaded from an untrusted source. That pattern is common in infostealer incidents. Attackers hide malicious code inside pirated software, keygens, fake installers, game cheats, and other popular downloads. When a user runs the downloaded file, the infostealer quietly installs itself and begins harvesting data from the browser.
Infostealers collect browser profiles, passwords, cookies, autofill data, credit card numbers, and sometimes files from cryptocurrency wallet extensions. The malware can also interact with remote command-and-control servers to receive updates and exfiltrate the stolen information. Many of these tools are sold as malware-as-a-service, meaning even low-skilled criminals can rent an infostealer and receive a steady stream of stolen logs. This type of ecosystem has made session theft faster, cheaper, and harder for individual users to detect.
Why AI accounts are now targets
The shift toward AI platforms is a natural development in the cybercrime economy. Paid AI assistants now behave almost like digital wallets. They hold valuable usage credits, API access, stored conversation data, and payment methods. An attacker who takes over a Claude account can consume credits for their own tasks, sell access to others, or use the account to run automated workflows at the victim's expense.
AI accounts also offer a lower risk of immediate discovery than traditional bank accounts. Many users do not monitor their AI usage closely, and the financial damage can be hidden inside a monthly subscription bill or a growing API invoice. By the time the victim notices, the attacker has already spent the credits and moved on. Because the account may contain sensitive business prompts, proprietary code, personal documents, or confidential meeting notes, the theft can create a privacy problem that goes far beyond the loss of a few dollars.
Cybersecurity researchers have warned for years that credential theft is evolving. Attackers once focused on email and social media accounts because those accounts could be used to reset other passwords and spread spam. Today, developer accounts, cloud consoles, and AI assistants are increasingly attractive. They contain high-value data and are directly connected to billing systems. The infrastructure used to steal from banks and online retailers is now being pointed at the newest generation of online services.
What affected users should do
The most important step is to remove the malware before doing anything else. Running a full malware scan with updated antivirus software is essential. Users should also uninstall any suspicious, cracked, or recently added software that might have carried the infostealer. If the malicious software remains on the machine, a new login session and a new payment card will simply be stolen again.
After the system has been cleaned, users should sign back into Claude, enable multi-factor authentication, and review account activity. Anthropic has already signed out affected users, which closes the session door that the attacker was using. A fresh login creates a new session and forces the user to verify that they own the account. Users should re-add payment details only after they are confident the infection has been removed.
It is also wise to check billing records. Unauthorized usage charges may appear as additional fees on a statement or as changes to a prepaid balance. Anthropic has said refunds are being processed, but users who notice unusual charges that have not been refunded should contact Claude support directly. In some cases, attackers may have used the account enough to generate charges that take time to identify.
Beyond Claude, affected users should consider changing passwords for other important accounts. Since infostealers collect everything from browser profiles, saved passwords and credit cards from other sites may also be at risk. Reusing the same password across multiple services makes the danger much worse.
The broader security lesson
The incident is a reminder that pirated software remains one of the most effective distribution channels for malware. Cracked games, fake productivity tools, and illegal downloads can deliver an infostealer in the same moment they deliver the promised application. The financial savings from using cracked software can disappear quickly when an attacker accesses an AI account, drains credits, and exposes sensitive personal data.
Enterprises face an even greater challenge. An employee who installs unofficial software on a company laptop can expose AI accounts, cloud services, and internal applications to a single infostealer infection. One stolen browser session may be enough for an attacker to move laterally into more valuable systems. Security teams should enforce strict software installation policies, maintain endpoint monitoring, and educate employees about the risks of downloading applications from untrusted sources. AI assistants have become core business tools, and their session data must be protected like any other corporate asset.
Anthropic has taken the immediate protective step of signing out users and wiping payment details. That reduces the danger of continued unauthorized use. However, the underlying malware still lives on the infected device until the user removes it. A clean computer, a changed password, and a cautious approach to downloaded software are the best defenses against the next round of AI-focused credential theft.
Source: ZDNET News