Anthropic has issued a warning about a wave of infostealer-driven account takeovers targeting paid Claude services. Attackers are exploiting stolen cookies and session tokens to hijack accounts and evade multifactor authentication (MFA), allowing them to mine valuable AI tokens at victims’ expense. The company has responded by logging out affected users and removing saved payment details, underscoring the growing threat to AI SaaS platforms from infostealer malware.
Infostealer Malware Targets Claude User Sessions
The latest attacks against Anthropic’s Claude AI platform began surfacing in August 2026, with users reporting unauthorised access to their accounts. The primary focus of these attacks is to gain access to premium Claude services using stolen credentials, sidestepping payment and verification barriers. According to emails shared by impacted users, Anthropic has been tracking a threat actor or group leveraging a range of well-known infostealer malware families. These include:
- Vidar
- LummaC2
- StealC
- RedLine
- Acreed
- Atomic Stealer
These malware strains are notorious for harvesting sensitive data from infected endpoints, such as browser cookies, session tokens, and login credentials. Once obtained, attackers can bypass traditional login mechanisms and MFA, as the tokens give them direct access to authenticated sessions.
Attack Timeline and Methods of Exploitation
The incident first drew public attention in late August 2026, when Reddit user WorriedAssociate7029 shared details of their experience. After suffering a social media account compromise, the user discovered malware on their system, which they believe arrived via a cracked game download. With assistance from Claude Opus 5 Max, they traced and cleaned the malware but soon received a warning from Anthropic about attempts to steal tokens via the Claude API.
The attack exploited session hijacking techniques:
- Infostealer malware infected the victim’s system and harvested active session cookies and Google account credentials.
- Using the stolen session tokens, attackers accessed the victim’s paid Claude account, bypassing MFA protections.
- Anthropic detected abnormal activity, logged the user out, and removed their saved payment method to prevent fraudulent usage.
Anthropic clarified in communications with affected users that the malware did not originate from Claude or its ecosystem. Instead, infostealers simply collected any active credentials found on infected endpoints, including those used to access Claude via Google sign-in. Once in possession of these tokens, attackers could access Claude’s paid features without detection until abnormal use was flagged.
Scope and Current Exploitation Status
While the attack was not traced to a vulnerability in Claude itself, Anthropic has acknowledged that the incident is part of a broader trend. Infostealer malware is increasingly being used to target AI SaaS accounts, with tokens becoming valuable commodities for resale or for mining high-value AI services. The company’s response included:
- Proactive logout of compromised sessions
- Removal of stored payment methods from affected accounts
- Email notifications to users with guidance on securing their accounts
Anthropic stated that there is no evidence of a breach within their own infrastructure or any new, AI-specific malware. Instead, this is a repurposing of traditional infostealer tactics for a new target: AI platforms where tokens and premium access are financially valuable.
Users have reported similar incidents on community platforms, indicating that the threat is not isolated to a single account or region. The exploitation is ongoing, with infostealer campaigns now actively harvesting tokens for multiple SaaS platforms, not just Claude.
Why This Attack Matters
The Anthropic Claude account takeover incidents highlight a shift in cybercriminal focus. As AI SaaS platforms gain popularity and tokens acquire monetary value, attackers are adapting old techniques to target new digital assets. This event underscores several key points:
- AI SaaS credentials and session tokens are now attractive targets for infostealers
- Session hijacking can bypass MFA, undermining a critical security control
- Endpoint hygiene and session management are crucial for SaaS security
What Organisations Should Do Next
Organisations using Claude or similar AI SaaS platforms should:
- Harden endpoints against infostealer malware with up-to-date security solutions
- Review session and SSO controls to detect and respond to suspicious activity
- Monitor AI SaaS usage for signs of fraud or unauthorised access
Prompt incident response and user education remain vital as attackers adapt their methods.
Originally reported by theregister.com.






