Anthropic is warning some Claude users that infostealer malware on their own computers has stolen their active Claude login sessions, letting attackers get into their accounts and burn through paid usage. The company is signing affected users out, removing saved payment cards, and refunding charges it identifies as fraudulent. The important detail for anyone who pays for an AI tool: this was not a breach of Claude itself. It was ordinary malware on personal machines copying an already-logged-in session, which sidesteps the password and two-factor login entirely. The theft can go unnoticed until your usage limit drains or an unexpected bill lands.
This piece reflects reporting as of September 2026. Anthropic has not disclosed how many accounts were affected; the figures below are from the company's account and independent security reporting.
What happened
According to security outlet BleepingComputer, which saw the notice Anthropic emailed to affected users, a bad actor has been taking Claude login sessions harvested by common infostealer malware and using them to run expensive prompts on other people's accounts. Anthropic told users the malware was not "related to Claude, installed through Claude", but rather general-purpose software that lands on a computer through dodgy downloads or malicious apps and scoops up whatever it can, including browser passwords, cookies and saved logins.
One user whose email was shared said their machine was compromised after downloading a pirated game, a classic infection route. Anthropic has linked the activity to several known infostealer families, including Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs.

Why stealing an AI login is now worth it
Infostealers have long gone after bank logins, crypto wallets and cloud accounts, because those turn into money. A paid AI subscription is a newer prize. An attacker with a hijacked session can run their own heavy workloads on your quota without paying for the compute, and on a large corporate plan that quota is worth real money. It is also stealthy: high-volume requests look normal on a usage dashboard, so the theft may only show up when limits hit or a bill arrives, unlike a bank transfer that trips alerts immediately.
The mechanism is the part worth understanding, because it is not specific to Claude. When you log in to a web service, your browser keeps a session cookie that proves you are already signed in, so you are not asked for your password on every visit. Infostealer malware copies that cookie. Loaded into an attacker's browser, it grants access as if they were you, and because two-factor authentication is only checked at the initial login, it does not get in the way. Any browser-authenticated service with a spending limit is exposed to the same trick.
What to do if you use Claude (or any paid AI tool)
The single most important point in Anthropic's guidance is that signing back in on an infected machine does not fix anything. As the company put it, signing you out stops the stolen sessions but does not remove the malware, so the next login can be stolen the same way. The practical steps:
- Assume the device, not the account, is the problem. If you have signs of unexplained usage, treat the computer as compromised and clean or rebuild it before logging back in.
- Remove the malware first, using reputable security software or a full device wipe, then change your credentials from a clean machine.
- Revoke active sessions where the service lets you, so any stolen session is cut off.
- Strip saved payment cards from the account until the device is secured, to limit what an attacker can spend.
- Avoid the usual infection routes: pirated software, cracked games and unofficial app downloads are how most of these infostealers arrive.

For businesses
The same advice scales up. Security writers covering the incident, including TechRound, note that organisations should treat shared AI accounts as high-value logins, not low-risk perks: put them behind single sign-on, set alerts for unusual consumption, shorten session lifetimes for accounts with billing access, and require re-authentication before payment details or plan limits can be changed. Token draining is easy to miss precisely because the cost stacks up quietly.
FAQ
Was Claude hacked?
No. Anthropic says this was not a breach of Claude. The malware ran on users' own computers and stole their logged-in sessions; the platform itself was not compromised.
How did attackers bypass two-factor authentication?
By copying an already-authenticated session cookie rather than logging in. Two-factor checks happen at login, so reusing a live session sidesteps them entirely. This is why the theft is not specific to AI tools.
Will I get refunded?
Anthropic says it is refunding charges it identifies as fraudulent and removing saved payment methods from affected accounts. It has not published figures on how many users were hit.
I signed back in and it happened again. Why?
Because signing out does not remove the malware. If the infostealer is still on your machine, your new session can be stolen too. The device has to be cleaned or rebuilt first.
The takeaway
This is less a story about Claude than about what an AI subscription has become: a paid account with real spending attached, and therefore a target. The reassuring part is that the platform was not breached and Anthropic is refunding fraudulent charges. The unglamorous part is that the fix sits with users, on their own devices, and the same weakness applies to any AI tool you log into through a browser. Basic hygiene, not logging in on a machine you do not trust, and keeping saved cards off accounts you do not actively guard, is what actually protects you here.
Sources
- BleepingComputer — Anthropic warns infostealer malware is hijacking Claude sessions to drain usage (30 August 2026)
- Malwarebytes Labs — Infostealers are hijacking Claude accounts at users' expense (September 2026)
- Help Net Security — Anthropic locks out Claude users after infostealers hijack login sessions (31 August 2026)
- TechRound — Malware is now stealing Claude sessions to drain paid AI usage (1 September 2026)