AI ONLINE6 September 2026
The AI News Desk

RelayON THE WIRE

The whole field of AI — read, checked, and explained.
Business & Funding

Infostealer malware is hijacking Claude sessions — and Anthropic is signing users out to stop it

The malware isn't on Anthropic's servers — it's on users' own PCs, copying the login cookie that keeps you signed in. That's enough to walk straight past two-factor authentication.

Priya AnandBy Priya AnandBusiness Editor
31 August 2026
Listen to this postread by Relay

If you use Claude and got signed out of your account this weekend, there is a reason — and it is worth understanding, because the same trick works far beyond one AI company.

From 30 August, Anthropic began contacting Claude users whose accounts had been compromised, signing them out, stripping saved payment methods from the affected accounts, and refunding charges that attackers had run up. The important detail, and the one that is easy to get wrong, is where the compromise happened. It was not a breach of Anthropic's systems. It was malware on users' own computers.

What actually got stolen

The culprit is a class of malware called an infostealer — programs that quietly sit on an infected PC and harvest whatever is useful: saved passwords, crypto wallets, and, increasingly, session cookies. Security researchers have tied this campaign to several well-known families, including Vidar, Lumma, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs.

A session cookie is the thing that keeps you logged in. When you sign in to a site, the server hands your browser a token so you do not have to re-enter your details on every page. Steal that token, and an attacker's browser can present it and be treated as you — already logged in.

Why two-factor authentication does not save you here

This is the part that makes session theft such a problem. Two-factor authentication protects the moment of logging in: it makes sure the person entering the password is really you. But once you are through that door, the session cookie is what holds it open — and the cookie is issued after 2FA has already been satisfied.

So an attacker replaying a stolen session never has to log in at all. They skip the password, skip the second factor, and arrive inside an account that is already open. In this case, that meant burning through victims' Claude usage and racking up charges on their saved cards.

What Anthropic did, and what it could not do

Anthropic's response was the correct one for this kind of attack: invalidate the stolen sessions by force-signing users out, so the copied cookies stop working, and remove the payment details and refund the fraudulent spend. That closes the specific hole.

What it cannot do is clean the malware off someone's computer — because that is not Anthropic's computer. If an infostealer is still running on your machine, it will simply capture the next session cookie after you log back in. The fix for the root cause is on the user's side: run a reputable malware scan, change passwords from a device you trust, and sign out of active sessions everywhere.

The wider point

It is tempting to read this as a Claude story, but session-cookie theft is not specific to Anthropic — it is one of the fastest-growing techniques in cybercrime, and it works against any service you stay logged in to, from email to banking. Anthropic is notable here mainly for spotting the pattern in its own usage data and acting on it visibly.

The uncomfortable takeaway is that "turn on two-factor authentication" — sound advice — is no longer the whole answer. If the device itself is compromised, the attacker can wait until you have done all the authenticating for them.

Tune your feed
Like to get more stories like this in your For You feed — dislike for fewer.
Sources
Priya Anand — Business Editor. Priya tracks the money and the market: raises, deals, pricing, and the economics shaping where AI goes next. Spot something wrong? Tell me and I'll correct it in public.
Got a question about this?

Ask Relay — he reads every question himself and replies personally by email.

Ask Relay →