Infostealers are draining Claude subscriptions with stolen session cookies, no password needed
Anthropic warned that commodity infostealers are lifting Claude session cookies from browsers and replaying them to drain paid usage. No password, no MFA prompt, and signing the user out stops the session without removing the malware.
Anthropic warned on August 30, 2026 that commodity infostealer malware running on users' own machines is extracting stored browser cookies and session identifiers for Claude accounts, then replaying them to consume paid usage. Because a session cookie represents an already-authenticated state, the attacker never sees a password and never meets an MFA prompt. Named families include Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer. Anthropic detected the abuse through unusual usage patterns, forced logouts, removed payment methods, and issued refunds. Its guidance to affected users is to change credentials, revoke active sessions, and clean the machine, with the pointed caveat that signing out of Claude stops the stolen session but does not remove the malware.
Why it matters
This is session cookie theft with a new billing target, and the mechanics are identical to every infostealer campaign of the last three years. What is worth noticing is which control failed: none of them, in the sense that authentication worked correctly and then stopped being consulted. A bearer cookie is valid wherever it is presented, so the security of the account reduces to the security of the endpoint holding it.
Anthropic's caveat is the part to carry into your own incident process. Revoking sessions is remediation of the symptom; the infected machine re-harvests the next session the moment the user signs back in. That makes endpoint cleanup a precondition for credential rotation, not a follow-up to it, which is the reverse of how most runbooks are ordered.
The durable control is binding the session to something the malware cannot copy. Token binding, device-bound sessions, and continuous access evaluation all attack the replay rather than the theft, which matters because the theft is not preventable from the service side. Anthropic's own detection path, anomalous usage rather than anomalous login, is also the right lesson for anyone defending an AI subscription: the sign-in looked fine, because it was.
Source: BleepingComputer
Related on Start with Identity
- Blog24,650 exposed server management interfaces leak crackable password hashes before login
Firmware security firm Lava found that 67 percent of 36,872 internet-exposed Baseboard Management Controllers hand over IPMI authentication hashes before a logi
- BlogA CVSS 10.0 Metabase zero-day handed admin access through the password reset endpoint
CVE-2026-72898 lets an unauthenticated attacker inject SQL through Metabase's password reset endpoint and take administrative control. It was exploited as a zer
- BlogA two-finger gesture let anyone holding a locked Android phone send SMS through Gemini, no PIN needed
A multi-touch gesture on Android 16's lock screen let anyone with physical access to a phone bypass the PIN prompt Gemini shows before sending SMS or WhatsApp m
- BreachInfostealers and session hijacking: stealing the session, skipping the login
Infostealer malware has made stolen session cookies a primary attack path, letting attackers ride an authenticated session and skip both the password and MFA en
- RankingBest Password Managers for Business: Top 5
The best business password managers in 2026: Bitwarden, Keeper, Dashlane, NordPass, and Zoho Vault. Ranked for team sharing, admin controls, SSO, and value.
- RankingBest Password Managers for Personal Use: Top 5
The best personal password managers in 2026: 1Password, Bitwarden, Proton Pass, NordPass, and Dashlane. Ranked for security, ease of use, passkeys, and family p