Claude sessions stolen by infostealers: MFA won't help
Anthropic is signing users out, wiping saved cards, and refunding charges after infostealer malware lifted live Claude session cookies. Session theft skips your password and your MFA.
Anthropic notified affected Claude users this weekend that a bad actor is using off-the-shelf infostealer malware to lift active Claude login sessions off people's computers, then spending those accounts' usage. The company is signing affected users out, removing saved payment methods, and refunding charges it identifies as unauthorized. The part worth your attention is not the AI vendor in the headline. It is the attack: stolen session cookies skip the password and skip the MFA prompt, and the same theft applies to every SaaS tab your team leaves open.
What actually happened
Per BleepingComputer's reporting on the notice Anthropic emailed to affected users, the company said it "recently became aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers."
The details:
- The malware is generic, not Claude-specific. Named families include Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on a small number of Macs. These are commodity stealers sold as a service.
- Delivery is the usual route — pirated downloads and malicious apps. Once resident, they scrape locally stored browser passwords, cookies, and credentials for whatever else is signed in.
- Anthropic was explicit that it has no reason to believe the malware is related to Claude, installed through Claude, or connected to anything users did with Claude.
- The tell was billing-shaped: usage limits that looked like they refilled and then drained while the account owner wasn't working.
- Anthropic's remediation — revoking sessions, pulling saved payment methods, refunding — kills the stolen cookie, because signing out cancels that session everywhere.
Signing out does not remove the malware. If the box stays infected, the next login gets stolen too.
Why session theft matters for your business
Most small teams treat MFA as the finish line. It isn't. MFA protects the login event. A session cookie is what the server hands you after that event — proof you already passed. Steal it and paste it into a fresh browser, and the attacker is inside with no password, no code, no push notification, no anomaly for you to notice.
That changes what you actually have to control:
Session lifetime is a security setting. Ask, per vendor, how long a session lives and whether you can shorten it. A 90-day remembered session on an admin account is a 90-day bearer token sitting in a cookie jar.
"Sign out everywhere" is your incident response button. Find it in every tool your team uses — Google Workspace, Shopify, Stripe, your AI vendors, your CRM — before you need it. Write the list down. When a laptop is suspected compromised, revoking sessions comes before the password reset, not after.
Saved payment methods are blast radius. Anthropic wiped them for a reason. Every stored card on a hijackable account is a spending limit you did not set.
The endpoint is still the whole game. Stealers land through pirated software and sketchy installers on machines your staff also use for work. Personal-device access to business SaaS is where this starts.
Finally: watch usage curves as a security signal, not just a cost line. The first evidence here was a bill behaving oddly. If nobody reconciles token spend to actual work, an intruder gets to be quiet.
Key takeaways
- Commodity infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, AMOS) stole live Claude sessions off user machines
- Stolen session cookies bypass both password and MFA — the login already happened
- Anthropic is revoking sessions, removing saved payment methods, and refunding unauthorized charges
- The malware is generic and unrelated to Claude; it steals browser cookies and credentials for everything signed in
- Signing out kills the stolen session but not the infection — reimage before re-authenticating
- Shorten session lifetimes, map the "sign out everywhere" control for every vendor, and reconcile usage spend
Can you revoke every session your team holds in under an hour? Most shops can name their MFA policy and nothing about session lifetime, saved cards, or which personal laptop still holds an admin cookie. We map the SaaS and AI surface a small team actually runs, set the revocation path per vendor, and wire usage anomalies into an alert instead of a monthly surprise. See how we build it, or send us your stack and we'll do the session audit.
Sources: BleepingComputer, Search Engine Journal.
- #session-hijacking
- #infostealer
- #anthropic
- #mfa
- #endpoint-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Thinkingbox: agents hit 65% once, 25% every time
Microsoft's Thinkingbox benchmark runs agents 20 times on the same business task. The best model passes once at 65%, all twenty times at 25%. Design for the gap.
Read itTeams Facilitator slips to November: don't plan around it
Microsoft's proactive Teams Facilitator moved from June to a November-December rollout, with no reason given. How to plan when a vendor roadmap keeps sliding.
Read it