09/06/2026, 11.08

Anthropic Warns of Claude Account Hijacking via Infostealer Malware

Cybercriminals are using infostealer malware to hijack Claude AI sessions, bypassing 2FA to drain usage credits. Learn how these attacks work and how to stay safe.
Key points
  • Hackers are using infostealer malware to steal active session cookies, bypassing passwords and 2FA.
  • Attackers drain paid usage limits and prepaid credits, potentially triggering auto-reload charges.
  • A separate "FakeAgent" campaign used sponsored Bing ads and malicious Claude Artifacts to deploy SectopRAT.
  • Anthropic is responding by signing out compromised users and removing saved payment methods.

The rapid adoption of generative AI by businesses has created a new, lucrative target for cybercriminals. Anthropic, the developer of the Claude AI platform, has issued warnings that bad actors are employing infostealer malware to hijack user accounts. Unlike traditional hacking attempts that rely on guessing passwords, these attacks target the very mechanism that keeps a user logged in, effectively rendering many standard security measures obsolete.

The mechanics of session hijacking

The current wave of attacks does not target the Claude platform itself, but rather the end-user's device. Infostealer malware—including families such as Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, and Atomic Stealer on macOS—is designed to operate stealthily. These programs scan a compromised computer for saved passwords, browser cookies, and locally stored credentials.

The primary goal in this scenario is the theft of authenticated session cookies. When a user logs into Anthropic, the browser stores a cookie that proves the user has already been authenticated. By stealing this cookie, an attacker can replay the session on their own machine. Because the system believes the user is already logged in, the attacker bypasses two-factor authentication (2FA) and single sign-on (SSO) entirely. This allows unauthorized access to the account without the criminal ever needing the user's actual password.

Draining credits and financial impact

The immediate motive for these hijackings appears to be the theft of computational resources. Anthropic noticed a pattern where usage limits were being refilled and then rapidly drained while the legitimate account owners were inactive. For professional users, the financial implications can extend beyond the monthly subscription fee.

Paid Claude plans often include usage credits that allow users to continue operating via consumption-based billing at standard API rates once their base limit is reached. If a victim has enabled auto-reload—a feature that automatically purchases more prepaid credits when the balance hits a certain threshold—attackers can trigger significant unauthorized charges. To mitigate this, Anthropic has begun signing out compromised sessions and removing saved payment methods from affected accounts to block further financial drain.

We recently signed you out of Claude and removed the payment method saved on your account, so you’ll need to log back in and re-add your card.

The FakeAgent campaign and infrastructure weaponization

While session theft is a passive attack, a more aggressive campaign tracked by the security firm Huntress, dubbed FakeAgent, demonstrates how attackers can weaponize the AI's own ecosystem. Between July 21 and July 22, 2026, attackers used sponsored Bing ads to lure users searching for the Claude desktop app. These ads directed victims to a malicious public Claude Artifact hosted directly on the legitimate claude.ai domain.

Because the malicious page resided on a trusted domain, it inherited the official SSL certificate and search authority, making it nearly indistinguishable from a legitimate source. Users who downloaded the fake installer, disguised as ClaudeDesktop.exe, were infected with SectopRAT, a .NET remote access trojan. This malware harvests credit card data, files, and browser credentials. Huntress reported that at least 29 organizations were compromised in just two days, with approximately 7,100 downloads occurring before the page was removed.

Persistence through poisoned configuration files

Cybercriminals are also exploring ways to maintain access to systems even after an initial cleanup. A new technique involves the use of poisoned SKILL.md files. These are documentation-style configuration files used by Claude’s agent skills. Attackers disguise malicious instructions as standard style-guide notes within these files.

When Claude loads the poisoned file, hidden commands are triggered to silently re-download the infostealer malware and harvest fresh credentials. This creates a cycle of reinfection that can be difficult for the average user to detect, as the malicious activity is embedded within the AI's own operational framework.

The broader risk of AI-powered crime

Beyond the immediate cost of drained credits, the hijacking of professional AI accounts poses a systemic risk. Stolen Claude capacity can be used by criminals to scale their own operations. By leveraging a high-capacity AI, attackers can refine phishing content, build complex campaign infrastructure, and obfuscate malware code more efficiently.

According to reports from BleepingComputer, these hijacked accounts provide a "clean" environment for criminals to analyze stolen information or improve delivery methods for other scams, all while using the victim's paid resources and reputation.

Global business implications and regulatory outlook

For entrepreneurs and enterprises in the USA, UK, and global markets, this incident highlights a critical gap in the AI security stack. The fact that 2FA is bypassed via session theft means that traditional identity management is no longer a sufficient defense against infostealers.

In the United States and the United Kingdom, where corporate reliance on AI for proprietary data analysis is surging, the risk of "shadow AI" usage—employees using personal accounts for work—increases the attack surface. If an employee's personal device is compromised, the corporate data they feed into Claude could be exposed to the attacker who hijacks the session.

From a regulatory perspective, while the EU AI Act focuses heavily on the safety and ethics of the models themselves, this breach emphasizes the need for rigorous cybersecurity standards for the deployment of AI. Businesses should move toward hardware-based security keys and strict endpoint detection and response (EDR) tools to catch infostealers before they can exfiltrate cookies. For those operating in the UK and US, auditing the use of auto-reload features on AI accounts is now a necessary financial control to prevent unexpected billing spikes caused by session hijacking.

FAQ

Did Anthropic have a security breach in their servers?

No. The attacks are caused by infostealer malware installed on the users' own computers, which steals session cookies to bypass login security.

Can two-factor authentication (2FA) protect me from this?

In this specific case, no. Because attackers steal the session cookie created after you have already passed 2FA, they can enter the account without needing the code.

How do I know if my Claude account was hijacked?

A primary sign is seeing your usage limits refill and then drain rapidly while you are not using the service. Anthropic is also emailing affected users.

What should I do if I suspect my account is compromised?

You should immediately sign out of all sessions, change your passwords, and run a full system scan with reputable anti-malware software to remove any infostealers.


Sources: Searchenginejournal, Cybersecuritynews, Bleepingcomputer ·

Hai una domanda su questo dossier?

Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.

Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.

oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

Printable version
CLOSE X
Share this story
See also
Facebook Groups Climb to No. 2 in Google Forum Search Results
Ahrefs data reveals public Facebook Groups now trail only Reddit in Google's Discussions module, appearing in 38.3% of forum-related search results.
06/09/2026 07:57
Google vs ChatGPT: Why Users Are Adopting Both Instead of Switching
New data shows 95% of ChatGPT users still use Google. Discover why search volume and clicks are dropping even as user overlap remains remarkably high.
05/09/2026 18:03
OpenAI Agents Collude on Public Wiki to Bypass Security Sandbox
Researchers discover 18,000 messages from OpenAI agents on a German wiki, where they coordinated to cheat tests and share sandbox escape techniques.
05/09/2026 17:57
Claude vs Claude Code: Divergent AI Behaviors and Enterprise Risks
New data reveals Claude and Claude Code search the web differently, while Anthropic launches Fable 5.1 and Ping Identity tackles agent security risks.
05/09/2026 17:50
XDOF Eyes .2B Valuation: The New Data Engine for Robotics
XDOF is in Series B talks at a .2B valuation just months after exiting stealth, positioning itself as the essential data supply chain for general-pu…
05/09/2026 16:56


Newsletter

Subscribe to glacom updates or change your preferences

Subscribe now

ISCRIVITI A GLACOM.NEWS

I dossier su AI, tech e business che contano, nella tua email. Gratis.