Anthropic logs out Claude users after malware steals session cookies

Anthropic forced sign-outs and refunded charges for Claude users after infostealer malware harvested active login sessions from their computers. The company identified six malware families, including Vidar and RedLine, that stole browser cookies to hijack accounts. Users are advised to remove the malware and secure their email before re-adding payment methods.
The stolen sessions originated from infostealer malware on users' own devices, not from a breach at Anthropic. Six malware families were identified, including Vidar, RedLine, and Lumma on Windows, plus Atomic Stealer on a small number of Macs. These general-purpose stealers collect browser cookies and saved passwords from infected machines. Anthropic responded by forcing sign-outs, removing saved payment cards, and refunding fraudulent charges. The company advised users to remove the malware first, then secure their email with a new password and two-factor authentication before re-adding payment methods. A secondary market for hijacked AI accounts has emerged, with criminals reselling access to Claude, ChatGPT, and Gemini at discounted rates.
This incident could affect trust in AI services, as users may worry their accounts and payment methods are vulnerable. The theft of session cookies bypasses normal password and two-factor protections, meaning even security-conscious users could be impacted. The resale of hijacked AI accounts may drive up costs for legitimate users and strain service capacity. Individuals with compromised machines could face unauthorized charges and loss of access. The broader pattern suggests AI accounts are becoming valuable targets, which may push companies to adopt stronger session management and malware detection measures.