Eigen RadarAI
Analysis

Anthropic forced Claude users offline after stolen session cookies hijacked their accounts

Infostealer malware lifted active Claude session cookies and replayed them to skip password and two-step checks, draining usage allowances and making unauthorised charges on affected accounts. Anthropic force-signed the accounts out, deleted saved payment cards and refunded the charges, though the step does not remove the malware itself. The company did not say how many accounts were hit or whether single sign-on seats were touched.

Artificial Intelligence··Night
At a bright home desk, a person seen from behind leans toward a blank-screen laptop; a disconnected external drive, cable, phone, box and cat sit nearby.

Stolen cookies let attackers skip the login entirely

VentureBeat reports that infostealer malware lifted active Claude session cookies from users' computers. Vidar, LummaC2, StealC, RedLine and Acreed lead the list on Windows, and Atomic Stealer stands out on macOS. Because a session cookie proves an earlier login, replaying it skips both the password screen and the second verification step, so the account changes hands without any warning to its owner. The outlet reports that the exposure runs to conversation history, uploaded files and authorised connectors including Gmail and Google Drive. The affected seats are card-billed individual accounts, and no Claude tenant administrator can revoke that access alone.[1]

Anthropic forced accounts offline and refunded the charges

Engadget reports that Anthropic force-signed the affected accounts out, deleted their saved payment cards and refunded the unauthorised charges, and told users that a usage allowance that refilled and then drained without their own activity was likely a sign of the attack. The forced sign-out also voids the cookie in the attacker's hands, because a cookie dies with the session that created it, but the outlet notes that the step does not remove the malware from the machine. Anthropic asked affected users to clean the malware first, change their email password and turn on two-step verification, and only then re-add a payment method. The company did not disclose how many accounts were affected.[2]

The tools are generic, and the risk outlasts the sign-out

The malware behind the theft is not Claude-specific: VentureBeat and Engadget both name Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer as general-purpose credential stealers, tools that can lift a session cookie from any service that relies on one. Anthropic's forced sign-out closes the stolen session, but the risk continues until the malware itself is removed from the affected device. Single sign-on protects Team and Enterprise seats, while the card-billed individual accounts hit here have no administrator able to revoke that access.[1], [2]

References

  1. News sourceVentureBeatClaude accounts were taken over with stolen session cookies that bypassed two-step login↩1↩2
  2. News sourceEngadgetAnthropic force-signed out Claude users over stolen session cookies↩1↩2