HeadlinesBriefing favicon HeadlinesBriefing.com

Anthropic Signs Out Claude Users After Infostealer Malware Attack

Engadget •
×

Anthropic automatically signed out Claude users after infostealer malware harvested active login sessions from users' PCs. The company deleted saved payment cards and refunded unauthorized charges while attributing the breach to malware on customers' devices rather than a direct attack on Anthropic. Security researchers identified six malware families responsible: Vidar, Lumma, Steal C, Red Line, Acreed on Windows and Atomic Stealer (AMOS) on Macs.

These general-purpose infostealers collect browser cookies and saved passwords, allowing attackers to replay stolen Claude session cookies and bypass authentication. Affected users were forced to remove malware, reset passwords, enable two-factor authentication, and re-add payment methods. The incident highlights growing criminal markets for hijacked AI accounts, with stolen Claude, ChatGPT, and Gemini credentials being trafficked at scale through proxy services known as transfer stations.