Infostealers hijack Claude sessions despite two-factor protection
August 31, 2026

Anthropic is warning about malware that copies active Claude sessions and causes unauthorized usage. Victims need to do more than change a password.
What this is about
Anthropic is warning affected Claude users about an active abuse campaign: common infostealers copy authenticated browser sessions and then use them to take over Claude accounts and consume paid usage. BleepingComputer published the warning on August 30, 2026, based on a message Anthropic sent to an affected account.
This is not a vulnerability in Claude itself. According to the information published so far, the malware reached computers through unofficial downloads or malicious apps. Anthropic named Vidar, LummaC2, StealC, RedLine and Acreed on Windows, as well as Atomic Stealer on a small number of Macs.
What the attack actually does
An infostealer searches an infected computer for data that can be monetized. That includes saved passwords, browser cookies and session identifiers. A session identifier tells a service that a user has already authenticated successfully. If an attacker copies that proof, they may be able to continue the same session from another machine.
That is why two-factor authentication offers limited protection in this situation: the attacker is not performing a fresh login and does not need to pass a second-factor challenge. They are taking over a state that has already been approved. Anthropic said one visible sign was usage limits refilling and then draining even though the account owner was inactive. The company signed affected sessions out, removed stored payment methods and said it would refund charges identified as unauthorized. This creates a concrete question for administrators: are concurrent sessions, unusual consumption spikes and new devices logged centrally? Without those signals, a hijacked account may remain unnoticed until the next bill.
Why it matters
Paid AI accounts have become a direct asset for criminals. A stolen account provides more than compute capacity. Depending on the product, it may contain chat histories, uploaded files, project context or connected services. The incident also demonstrates that standard account-security advice is insufficient when the endpoint itself is compromised.
This matters especially for organizations because browser sessions often remain valid longer than a single workday. A company that uses Claude on managed devices should not treat unexplained consumption only as a billing problem. It can be an indicator that other browser sessions, credentials and local secrets were copied as well.
In plain language
Imagine a hotel that checks a guest's identity and then gives them an electronic room key. Two-factor authentication is the strict check at reception. An infostealer copies the already activated room key instead. The thief does not return to reception; they try to open the door directly with the copy.
A practical example
A developer uses Claude every day and protects her account with two-factor authentication. After downloading a tampered application, an infostealer copies her browser cookies. The next morning, the account shows unusually high usage even though she did not work overnight.
She immediately changes her Claude password. That alone may not be enough if the copied session remains valid or the infostealer is still running. The appropriate response is broader: revoke every active session, isolate and professionally clean or reinstall the computer, change passwords from a clean device, inspect saved payment methods and check other accounts for suspicious activity. Only then should she sign in again.
Scope and limits
- Public details come mainly from Anthropic's message to affected users and individual reports. The campaign's scale, victim count and total financial damage have not been disclosed.
- An empty usage allowance does not prove an infostealer infection. Billing faults, team usage or a different compromised access path also need investigation.
- Signing out a session does not remove malware. Changing only the password can lead to immediate reinfection. Conversely, users should not declare a machine clean solely because an AI model says so; serious cases warrant expert analysis or a fresh installation.
SEO & GEO keywords
Claude, Anthropic, infostealer, session theft, browser cookies, two-factor authentication, Vidar, LummaC2, Atomic Stealer, account security, AI security
💡 In plain English
Malware can copy an already authenticated Claude session and thereby bypass two-factor protection. Victims should revoke all sessions and clean the computer before using new credentials.
Key Takeaways
- →Anthropic named six infostealer families across Windows and macOS.
- →Stolen session cookies can bypass a new two-factor challenge.
- →Usage limits draining unexpectedly can be a warning sign.
- →Signing the account out does not remove the malware.
- →Other credentials stored on the affected computer should also be considered at risk.
FAQ
Is Claude itself infected with malware?
Anthropic says no. The named infostealers arrive through other downloads or malicious applications.
Does two-factor authentication stop this attack?
Not reliably when an attacker copies an already authenticated session. Two-factor protection remains important but cannot replace endpoint security.
What should affected users do first?
Revoke active sessions, disconnect the computer and use a clean device to inspect other accounts and payment methods.