Infostealer Malware Reportedly Hijacked Active Claude Sessions

THE BRIEF
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions. The supplied report says attackers can use those sessions to access accounts and consume their Claude usage. The available information does not establish how many users were affected, how the malware reached their computers, what account activity occurred beyond usage consumption, or whether the activity is still continuing. It also does not identify particular industries, companies, or geographic areas. The reported issue centers on stolen authenticated sessions rather than a confirmed compromise of Claude itself. That distinction matters: the supplied facts describe malware on users’ PCs and unauthorized use of affected accounts, but they do not demonstrate a broader service-wide incident. Organizations using Claude should treat unexpected usage or unfamiliar account activity as a reason to investigate the relevant endpoint and account. This report is partially verified, so its details should be handled as a warning requiring confirmation rather than as a complete incident assessment.
WHY IT MATTERS
A stolen active session can give an attacker access to an already authenticated service account. In this case, the reported outcome is unauthorized Claude access and consumption of the affected user’s usage. That can create operational disruption, unexpected costs, and uncertainty about account activity, although the supplied facts do not confirm any particular financial or data impact. The incident also reinforces that protecting endpoints is important even when users believe their account credentials are secure. Organizations should connect endpoint findings with service-account monitoring instead of treating unusual usage as only a billing issue.
WHO SHOULD CARE
Security, identity, endpoint, cloud, and AI governance teams should care, along with employees who use Claude on company computers. Account owners and help desks should know how to recognize and escalate unexpected usage or unfamiliar session activity.
WHAT TO DO NOW
- Review endpoint detections for infostealers on computers used to access Claude.
- Investigate unexpected Claude usage, unfamiliar account activity, and unusual session behavior.
- Revoke active sessions and reauthenticate affected accounts according to internal response procedures.
- Confirm whether company devices permit Claude access through managed, monitored endpoints.
- Remind users to report suspected malware and unexpected account activity promptly.
VERIFICATION NOTE
Published from the SecBriefs public CMS view with partially verified status.