❯ Anthropic signs users out and refunds charges after infostealers hijack Claude sessions
what Anthropic didAnthropic is notifying some Claude users that infostealer malware on their computers stole active Claude login sessions, letting attackers get into accounts and burn their usage. The response is three things: signing affected users out, removing saved payment methods, and issuing refunds for charges identified as unauthorized.
why 2FA didn't stop itPer BleepingComputer, this malware family historically went after browser passwords and banking credentials; here it turned to AI subscriptions. Because attackers reuse a valid session, they can bypass the normal password and two-factor flow. The variants involved include Vidar, LummaC2, StealC, RedLine and Acreed on Windows, with a smaller number of Mac users hit by Atomic Stealer. Anthropic stressed it has “no reason to believe this malware is related to Claude or was installed through Claude”; such programs typically arrive via downloads or malicious apps and take locally stored browser passwords, login cookies and other apps’ credentials.
accounts as a consumableThe motive is what deserves separate attention: this is theft not of data but of compute allowance. Once a model subscription is priced by usage, the session itself becomes an asset with cash value — an economic incentive credential theft never had before. Enterprise governance of AI accounts has to follow: single sign-on, session lifetimes and anomalous-usage alerting, all built for SaaS, now need to cover model subscriptions.
▪ SIGNALA valid session is money; AI subscription quota has become something malware can monetize directly.