Anthropic has identified at least five widespread infostealer programs that steal active login sessions from Claude users and empty their accounts. Affected accesses are automatically logged out, stored payment methods are deleted, and unauthorized charges are reimbursed. According to Anthropic, the malware reaches computers through pirated programs or fake apps, not through Claude itself. The number of affected accounts remains unclear.
Image generated with GPT Image 2
Key takeaways
Five known malware programs such as Vidar and LummaC2 steal active login sessions directly from the computer.
Stolen session cookies completely bypass password and two-factor authentication.
Anthropic automatically removes affected payment data and reimburses identified erroneous charges.
Logging out alone does not remove the malware from the infected computer.
Affected users should change their access data, revoke other sessions, and clean their system.
Smartphones and tablets are not affected according to current knowledge.
Anthropic has identified so-called infostealer malware – software that reads credentials from infected computers – as the cause of hijacked Claude accounts. The programs copy active login sessions and use them to take over foreign accounts and exhaust their usage limits. Anthropic automatically logs out affected users, removes stored payment methods, and refunds unauthorized charges.
As BleepingComputer reports, citing an email from the company to affected users, at least five widespread malware programs are behind the attacks on Windows computers: Vidar, LummaC2, StealC, RedLine, and Acreed. For a smaller number of Mac users, Anthropic also identified the malware Atomic Stealer. The malware usually enters the computer through pirated software or fake apps and reads passwords, browser cookies, and credentials from other programs, not just Claude. With the stolen session, attackers completely bypass password and two-factor authentication because the session is already logged in; affected users often only notice the abuse when their usage limit fills up and empties again without their intervention. However, logging out does not remove the malware from the device; affected users should change their credentials and additionally clean the computer.
The case is part of a growing series of attacks on credentials related to AI tools: just in July, a compromised npm package deliberately injected infostealers into programming tools like Claude Code. Anthropic has not yet published the total number of affected Claude accounts.
It remains open whether Anthropic will introduce additional protective measures in the future, such as binding sessions to individual devices, rather than just reacting afterwards. For office users, the case primarily shows: a clean account does not protect if one’s own computer is infected – the gap lies outside of Claude.
Frequently asked questions
How can I tell if my Claude account was affected?
A typical sign is a usage limit that fills up without any activity and shortly thereafter empties again; affected users also receive an automatic logout and an email from Anthropic.
Do I need to change my password if I am affected?
Yes. Anthropic recommends changing the password, revoking all active sessions, and additionally checking the computer for malware, as simply logging out does not remove the malware.
Are smartphones or tablets also affected?
According to current knowledge from Anthropic, no – the known attacks only affect infected Windows computers and, to a lesser extent, macOS computers.
Will I get my money back if my account was abused?
According to Anthropic, they reimburse charges that they identify as unauthorized and simultaneously remove the stored payment method from the affected account.
Is the security vulnerability a problem of Claude itself?
No. According to Anthropic, the malware does not originate from the use of Claude, but independently reaches the computer through pirated programs or fake apps.
Brian Beckmann: “Anthropic warns of malware that takes over Claude accounts.” Beckmann, August 31, 2026, https://beckmann.ai/en/security/2026-08/anthropic-infostealer-claude-accounts.