Anthropic has told some Claude users their accounts were accessed without their knowledge — not through a stolen password, but through malware already sitting on their computer. The company says infections from common infostealer families, including Vidar, Lumma, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on a small number of Macs, harvested the browser cookies that keep a Claude login session active. Anyone holding that cookie can act as the logged-in user without ever needing the password or a one-time MFA code, because the session itself is already authenticated.
Anthropic says it detected the anomalous activity, signed the affected sessions out, stripped saved payment methods from those accounts as a precaution, and refunded any usage it identified as unauthorized. The malware itself is not Claude-specific: it is the same general-purpose credential-and-cookie-stealing software that spreads through pirated software installers, cracked games, and fake "update" downloads, and it grabs session cookies for whatever accounts happen to be logged into the infected browser at the time — banking, email, cloud consoles, and AI tools alike. If a Claude account's usage looked like it refilled and then drained on its own, an infected device is the likely explanation.
What this means for your business
Any account your team accesses through a browser, not just Claude, is exposed the same way once a device is infected: password resets and MFA don't help, because the attacker rides the already-open session rather than logging in fresh. If anyone on staff uses AI coding or chat tools for work, treat their laptop hygiene as a business control, not a personal one — block unofficial software downloads, keep endpoint protection active and updated, and route company AI accounts through single sign-on where you can, since SSO sessions are easier to revoke centrally than a scattered set of individual logins. Watch billing dashboards for AI tools the same way you'd watch a company credit card: a sudden overnight usage spike is often the first visible sign of a hijacked session, well before anyone notices anything else is wrong. If you suspect a device is infected, don't stop at changing the password — sign the account out of every active session (most SaaS admin panels and AI platforms have this option) and treat it as a fresh credential and fresh MFA enrolment, not a reset.