Anthropic Users Targeted by Infostealers as Stolen Sessions Give Attackers a Way Around MFA + Video

Listen to this Post

Featured Image

A New Warning for Claude Users

A disturbing security incident involving Anthropic users highlights a growing weakness in modern account security: attackers no longer necessarily need to steal a password to take control of an account.

Anthropic has warned an unknown number of Claude users that threat actors obtained their active login sessions after infostealing malware infected their Windows or Mac computers. The attackers could then use those stolen sessions to access Claude accounts as if they were already authenticated users.

The incident is particularly important because it demonstrates why strong passwords and multifactor authentication alone are no longer enough. If malware steals the browser cookies, authentication tokens, or session information created after a successful login, an attacker may be able to reuse that authenticated state without having to defeat the user’s password or MFA challenge.

Anthropic responded by forcing affected users to sign in again, invalidating stolen sessions, removing saved payment methods, and refunding unauthorized Claude charges where applicable. But the company also delivered a much more important warning: logging out is not enough if the malware remains on the computer.

How the Claude Account Attacks Happened

Anthropic’s investigation indicates that the attackers did not compromise Claude itself. Instead, they relied on infostealers that were already present on users’ devices.

The malware was apparently installed through malicious applications, unofficial software downloads, or other forms of unwanted software. Once active, these information-stealing programs could search browsers and systems for valuable authentication material.

The infostealers identified in the campaign included Vidar, Lumma/LummaC2, StealC, RedLine, and Acreed on Windows systems, along with Atomic Stealer, also known as AMOS, affecting a smaller number of Mac users.

This distinction matters. The reported compromise was not described as an attack in which hackers broke directly into Anthropic’s infrastructure and extracted Claude credentials. Instead, compromised endpoints became the starting point for the attack.

The Malware May Have Been Hiding for a Long Time

One of the more concerning details is that affected users may have had the infostealers installed for some time before their Claude sessions were abused.

Infostealers are designed to operate quietly. They can collect browser cookies, saved credentials, session tokens, cryptocurrency wallet information, autofill data, and other sensitive material without necessarily producing obvious symptoms.

That means a user might notice nothing unusual until an online account begins showing suspicious activity.

In a modern browser-centric environment, the browser itself has effectively become a high-value credential store. Whoever gains access to the information stored inside it may obtain a map of the victim’s digital life.

Why Session Theft Is More Dangerous Than Password Theft

Traditional credential theft usually focuses on obtaining a username and password.

Session theft attacks a different layer.

After a legitimate user successfully authenticates, a website or service creates session information that tells the server the user has already passed authentication. Depending on the architecture, that information can include cookies, tokens, or other authentication artifacts.

If an attacker obtains a reusable session artifact, they may be able to impersonate the already-authenticated user.

That is why MFA can sometimes be bypassed indirectly. The attacker does not necessarily need to convince the service that they know the password and possess the second factor. Instead, they attempt to reuse authentication material generated after those checks have already succeeded.

MFA Is Still Important, But It Is Not Magic

The Anthropic incident should not be interpreted as evidence that multifactor authentication is useless.

MFA remains one of the most important defenses against credential theft.

The problem is that authentication does not automatically guarantee the security of every session created afterward. Once a user has authenticated, malware running on the endpoint may attempt to steal the resulting session information.

This creates a difficult security problem: the strongest login process in the world cannot fully compensate for a compromised endpoint.

Organizations therefore need to think beyond passwords and MFA. Device security, browser protection, token management, session invalidation, endpoint detection, and identity monitoring all become part of the same security chain.

Anthropic Forced Affected Users to Log In Again

Anthropic responded by signing affected users out of Claude.

This action was designed to invalidate the stolen sessions used by attackers. Once those sessions were revoked, the threat actor could no longer continue using those particular authentication artifacts.

Affected users would then need to authenticate again on their devices.

This is an important response because changing a password alone may not immediately terminate every active session. Security teams must understand which authentication tokens remain valid and revoke them when compromise is suspected.

Saved Payment Methods Were Also Removed

Anthropic also removed saved payment information from compromised accounts.

That was an important precaution because attackers had apparently been consuming users’ allotted Claude usage, and there was a possibility of unauthorized charges.

Where compromised payment cards had already been used to pay for Claude usage, Anthropic said unauthorized charges were refunded.

The financial component makes this incident more serious than a simple account takeover. A compromised AI account can potentially become a resource that attackers consume, particularly when accounts have paid usage limits or access to powerful AI capabilities.

What Were the Attackers Doing Inside Claude?

One major question remains unanswered.

Anthropic did not publicly establish what the attackers ultimately intended to accomplish with the compromised Claude accounts.

The attackers consumed some

Compromised AI accounts could theoretically be valuable for a variety of reasons, including unauthorized experimentation, automated workloads, abuse of paid resources, reconnaissance, or simply monetizing access.

The lack of a clearly established motive is therefore one of the most interesting unresolved aspects of the incident.

Chrome Credentials Could Reveal Much More Than Claude Access

A compromised Claude session may only be one piece of the problem.

The same infostealer could potentially have harvested browser cookies, saved passwords, autofill information, and authentication artifacts belonging to other websites.

That means an infected computer should not be treated as having a single compromised account.

It should be treated as a potentially compromised digital identity environment.

A user who discovers an infostealer on their computer should therefore think beyond Claude. Email, cloud storage, banking, work accounts, social networks, password managers, developer platforms, cryptocurrency services, and other browser-accessible systems may also require investigation.

Why Password Changes Must Come Later

Anthropic’s guidance follows an important security principle: clean the infected system before assuming that new credentials are safe.

Imagine changing a password while malware is still running on the computer.

If the malware can continue monitoring browser activity or harvesting authentication information, the newly created credentials may simply become the next thing stolen.

The safer sequence is to isolate or clean the compromised device, verify that the malware is gone, and then reset important credentials from a trusted environment.

Securing the Email Account Is Especially Important

Anthropic also recommended securing the email account used with Claude.

This is critical because email accounts often sit at the center of modern identity systems.

An attacker who controls an email account can potentially initiate password resets for other services, intercept security notifications, or maintain persistence even after individual passwords are changed.

For this reason, the email account should be treated as a priority during incident recovery.

Sign Out of Other Devices

Users affected by the incident were advised to sign out of other devices.

This is another important step because an attacker may have established or retained sessions beyond the one that originally triggered the security alert.

A complete recovery process should therefore consider active sessions across browsers, computers, phones, tablets, and other connected devices.

The objective is simple: reduce the number of authentication states that an attacker might still control.

Review Every Saved Browser Password

The incident also provides a strong reason to audit saved browser credentials.

If an infostealer had access to a browser profile, changing only the Claude password could leave dozens of other accounts exposed.

Users should review important accounts and prioritize those capable of causing the greatest damage.

Email, banking, work accounts, cloud services, developer accounts, social media, password managers, and financial platforms deserve particular attention.

Do Not Add Payment Information Back Too Quickly

Anthropic advised affected users to wait before adding a payment method back to their Claude account.

That advice makes sense.

The account should first be secured, the infected system should be cleaned, credentials should be rotated where necessary, and unauthorized sessions should be revoked.

Only after those steps have been completed should sensitive payment information be restored.

The Broader Infostealer Economy

The Claude incident fits into a much larger cybersecurity trend.

Infostealers have become an efficient way for criminals to turn infected consumer computers into credential-harvesting machines.

Instead of attacking a major technology company directly, attackers can compromise individual endpoints and let malware collect authentication material from thousands of victims.

That changes the economics of cybercrime.

A single malware infection can potentially expose multiple online services, creating a much larger attack surface than the original infection suggests.

Why AI Accounts Are Becoming Attractive Targets

AI accounts are increasingly valuable because they are no longer simple chat applications.

Users may connect AI services to business workflows, developer tools, APIs, documents, code repositories, cloud systems, and payment methods.

A stolen account can therefore represent more than access to conversations.

It can potentially provide access to valuable computational resources, sensitive information, integrations, and organizational workflows.

As AI adoption expands, attackers are likely to view AI identities as another major category of digital credentials.

The Endpoint Is Becoming the New Security Battleground

The Anthropic incident reinforces a fundamental security lesson.

Authentication protects the account, but the device performs the authentication.

If the device is compromised, attackers may attempt to steal the artifacts created by that authentication process.

This makes endpoint security inseparable from identity security.

Strong authentication, secure browsers, operating-system protections, application controls, malware detection, and user awareness all have to work together.

Deep Analysis: How Session Theft Changes the Security Equation

The Authentication Chain

Modern authentication can be viewed as a chain:

Username

Password

MFA / Passkey / Security Check

Authenticated Session

Session Cookie / Token

Access to Application

The traditional attacker tries to break the first few stages.

An infostealer may instead target the later stages.

Inspect Active Sessions

On a Linux system, administrators can begin investigating suspicious authentication activity with commands such as:

who
w
last
lastlog

These commands can help identify unexpected logins or sessions.

For network connections, administrators can inspect active connections with:

ss -tunap

On Windows, defenders can review active network connections with:

Get-NetTCPConnection | Sort-Object State

These commands do not specifically identify stolen Claude sessions, but they can help establish whether a system is behaving unexpectedly.

Search for Suspicious Processes

On Linux:

ps aux --sort=-%cpu | head -30

On Windows PowerShell:

Get-Process | Sort-Object CPU -Descending | Select-Object -First 30

Unfamiliar processes deserve investigation, particularly if they appeared after installing unofficial software.

However, process inspection alone is not sufficient. Modern malware can hide, inject into legitimate processes, or terminate itself after collecting information.

Examine Recently Installed Software

On Windows, defenders can review installed applications through system management tools and PowerShell.

For example:

Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\ |
Select-Object DisplayName, DisplayVersion, Publisher

The same should be done for the relevant user-level software locations.

The goal is not simply to delete anything unfamiliar. Security teams should preserve evidence where possible before removing suspected malware.

Check Persistence Locations

On Linux, common persistence mechanisms can be investigated with:

systemctl list-unit-files --state=enabled
crontab -l

On Windows, defenders should examine scheduled tasks:

Get-ScheduledTask | Where-Object {$_.State -ne "Disabled"}

Again, these are investigation techniques rather than proof that a machine is clean.

Browser Credentials Require Special Attention

Infostealers frequently target browser data because browsers contain valuable authentication artifacts.

Security teams should therefore treat a compromised browser profile as potentially exposed.

Simply deleting one cookie is not a complete recovery strategy.

If malware accessed the browser profile, assume that credentials and session information stored there may have been exposed until proven otherwise.

Revoke Sessions at the Service Level

The strongest response occurs on the server side.

Services should provide mechanisms for users and administrators to revoke:

Active sessions

Refresh tokens

Remember-me sessions

API tokens

OAuth grants

Trusted devices

Revoking only a password may not be sufficient when previously issued tokens remain valid.

Rotate Secrets After Endpoint Cleanup

For developers and organizations, incident recovery should also include checking:

git config --global --list

and reviewing environment variables:

env | sort

The objective is to identify potentially exposed credentials such as API keys, cloud credentials, repository tokens, and service secrets.

Never paste real secrets into a command or public log while performing this investigation.

A Better Incident-Response Sequence

A practical response can follow this order:

1. Isolate suspected infected device

2. Preserve evidence if necessary

3. Remove or investigate malware

4. Revoke active sessions

5. Secure primary email account

6. Rotate important passwords

7. Rotate API keys and tokens

8. Review financial accounts

9. Check other devices

10. Monitor for continued compromise

This sequence reduces the chance of repeatedly replacing credentials while the attacker still has access to the endpoint.

What Undercode Say:

Session Theft Is the Real Story

The most important part of this incident is not simply that Claude accounts were compromised.

The deeper story is the growing value of authenticated sessions.

Passwords Are No Longer the Only Target

Attackers understand that stealing passwords has become more difficult.

MFA, passkeys, password managers, and risk-based authentication have raised the cost of traditional credential attacks.

Session theft provides another route.

Infostealers Are Extremely Efficient

The attacker does not necessarily need a sophisticated zero-day exploit.

A victim can install a malicious application, unknowingly execute a compromised installer, or download pirated software.

The infostealer then performs much of the credential-harvesting work automatically.

One Infection Can Become Many Breaches

A single compromised browser can expose multiple services.

Claude may be only one visible consequence.

The same malware could potentially target email, banking, social networks, cloud platforms, developer services, and corporate applications.

AI Accounts Have Become Valuable

AI services are becoming infrastructure.

Businesses are increasingly using AI accounts for development, research, automation, writing, coding, analysis, and customer workflows.

That makes unauthorized AI access increasingly attractive to criminals.

Usage Theft Is a Real Security Problem

Attackers consuming Claude usage may seem less serious than stealing money.

It is not.

Computational resources have economic value.

A compromised account can become an unauthorized resource that someone else consumes.

Payment Protection Was Necessary

Removing saved payment methods was therefore a sensible containment step.

It limits the financial consequences while the investigation continues.

Forced Logout Was Also Necessary

Invalidating compromised sessions cuts off the stolen authentication state.

Without server-side revocation, attackers could potentially continue using previously captured sessions.

But Logout Cannot Clean Malware

This is the critical limitation.

If the infostealer remains installed, the attacker may simply steal the next session.

That turns recovery into a cycle.

Endpoint Cleanup Must Come First

Users need to understand that account recovery and device recovery are connected.

Changing credentials from an infected computer can expose the new credentials.

Email Should Be Treated as the Master Key

Email accounts often control password recovery for many other services.

They should therefore receive priority during incident response.

Browser Password Storage Has Risks

Browser password managers are convenient and increasingly secure, but a compromised endpoint changes the security equation.

The endpoint remains a critical trust boundary.

MFA Still Matters

The incident does not prove that MFA failed as a technology.

Instead, it demonstrates that MFA protects an authentication event, while session theft attacks what happens afterward.

Passkeys Are Not a Complete Endpoint Defense

Passkeys can dramatically improve resistance to phishing and password theft.

But they cannot magically make an infected computer trustworthy.

Endpoint compromise remains an important problem.

Security Teams Need Token Visibility

Organizations should monitor session creation, unusual device changes, geographic anomalies, and suspicious token behavior.

Identity security needs to extend beyond password authentication.

AI Companies Face a New Security Category

AI providers now need to treat account abuse as an infrastructure-security concern.

Their customers are paying for access to computational resources.

Those resources can become attractive targets.

Session Revocation Should Be Easy

Users should be able to see active sessions and revoke them quickly.

Security controls that require complicated support interactions are less useful during an active incident.

Device Trust Is Becoming More Important

A login from a previously trusted device should not automatically remain trusted forever.

Risk can change after malware infection or unusual activity.

Browser Isolation May Become More Common

Organizations handling sensitive data may increasingly separate business credentials from general browsing environments.

That limits the damage caused by malicious downloads.

Software Provenance Matters

Unofficial installers remain a significant risk.

Users should understand where software originates before executing it.

Pirated Software Can Be a Security Trap

Cracked applications and unofficial utilities are particularly attractive delivery mechanisms for infostealers.

Free software can carry a very expensive hidden cost.

Personal Devices Can Become Enterprise Risks

Employees frequently use personal computers to access business services.

One infected home computer can therefore become an enterprise identity problem.

AI Usage Needs Monitoring

Organizations should monitor abnormal increases in AI consumption.

A sudden spike can sometimes reveal account compromise before the user notices anything else.

API Keys Are Another Target

AI users increasingly connect services through APIs.

An infostealer that reaches developer environments could potentially expose credentials that are even more valuable than an individual web session.

Cloud Credentials Deserve Special Attention

If an infected workstation has cloud credentials stored locally, the consequences could extend far beyond a single AI account.

This is why developers should avoid leaving long-lived secrets exposed on endpoints.

Token Rotation Should Be Routine

Short-lived credentials reduce the window available to attackers.

Long-lived tokens create a larger persistence opportunity.

Security Is Becoming More Layered

The old model was:

Password + antivirus.

The modern model needs to be closer to:

MFA + endpoint security + token controls + behavioral monitoring + session management.

Users Need Better Recovery Guidance

Security alerts should clearly tell users what to do next.

Anthropic’s guidance is useful because it explains that signing out is only one part of the recovery process.

Incident Communication Matters

Users need to know what was compromised, what was revoked, and what they must do themselves.

Vague warnings can leave victims exposed.

The Industry Should Expect More Session Attacks

As password security improves, attackers will continue searching for alternative authentication paths.

Session theft is therefore unlikely to disappear.

AI Accounts Will Become Bigger Targets

The more valuable AI becomes, the more attractive stolen AI identities become.

This incident may be an early example of a much larger trend.

The Biggest Weakness May Be the

Cloud providers can operate extremely strong infrastructure.

But they cannot completely control every endpoint connecting to their service.

The

The Security Lesson Is Simple

If malware can control the device, it may eventually control the identities used from that device.

That is the lesson Claude users should take from this incident.

✅ Anthropic’s Response Included Forced Logouts

Anthropic reported that affected users were signed out and that the sessions associated with the compromise were invalidated.

That is an appropriate containment measure because stolen authentication sessions must be revoked server-side rather than relying solely on password changes.

✅ Infostealers Were Reported as the Source of the Compromise

The incident was attributed to general-purpose infostealing malware installed on affected users’ systems, rather than malware delivered through Claude itself.

Anthropic identified Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer among the malware associated with the campaign.

✅ MFA Can Be Undermined by Stolen Sessions

The broader security claim is accurate: if an attacker obtains a valid authentication session after MFA has already been completed, they may be able to use that session without repeating the original authentication process.

This is why session and token protection are increasingly important components of identity security.

❌ Changing a Password Alone Does Not Guarantee Full Recovery

A password reset is important, but it does not automatically prove that every stolen session, token, API key, or compromised device has been neutralized.

If malware remains on the endpoint, newly generated authentication information may potentially be exposed again.

Prediction

(+1) Session Protection Will Become a Major AI Security Feature

AI platforms are likely to improve session management, active-device visibility, token revocation, suspicious-login detection, and automated account lockdown.

Users will increasingly expect to see exactly where their AI accounts are logged in.

(+1) AI Providers Will Increase Account-Abuse Detection

Unexpected usage spikes, unusual locations, unfamiliar devices, and abnormal API behavior are likely to become stronger signals for detecting compromised AI accounts.

This could reduce the financial impact of stolen accounts.

(+1) Passkeys and Strong MFA Will Continue Growing

Despite this incident, stronger authentication remains essential.

Passkeys, hardware-backed authentication, and phishing-resistant MFA can significantly reduce traditional credential theft and should remain part of modern identity strategies.

(-1) Infostealer Attacks Will Continue Expanding

As long as browsers contain valuable authentication material and users continue downloading untrusted software, infostealers will remain attractive to criminals.

The threat is unlikely to disappear simply because password security improves.

(-1) AI Accounts Could Become a New Cybercrime Commodity

As AI services become more powerful and expensive, stolen accounts may increasingly be traded, abused, or used to consume computing resources.

The Claude incident demonstrates why AI identity security should be treated as seriously as email, cloud, and developer-account security.

Final Security Perspective

The Anthropic incident is a reminder that modern account security does not end when the login screen disappears.

The most valuable thing on a compromised computer may not be the password sitting inside the browser.

It may be the authenticated session that proves the user has already passed every security check.

That changes the defensive strategy. Users need secure devices, trusted software sources, strong authentication, careful credential management, session revocation, and rapid incident response.

For Claude users affected by this incident, the safest approach is to think beyond the AI account itself. Clean the device, revoke sessions, secure email, rotate important credentials, review other accounts, and only then restore sensitive information such as payment methods.

The bigger lesson for the industry is even clearer: as authentication gets stronger, attackers will increasingly target what comes after authentication.

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube