Anthropic has locked out a group of Claude users after infostealer malware was used to hijack their active login sessions, according to a report from Help Net Security. The company identified that stolen session tokens were being used to access accounts without passwords, prompting it to force sign-outs and cut off the unauthorized access. The incident adds to a string of security events that have put Anthropic's platform in the spotlight over recent months.

How the Attack Worked

Infostealers are a category of malware designed to quietly harvest credentials and session cookies from infected devices. Once a session token is stolen, an attacker can authenticate as the victim without needing a username or password, bypassing multi-factor authentication entirely. In this case, the stolen tokens granted direct access to Claude accounts, potentially exposing conversation history, API keys, and billing information. This pattern is consistent with what researchers have flagged as a growing threat to AI platform users. It also follows a separate incident in which Anthropic force-signed out users and wiped saved payment cards after a prior session theft campaign.

Key Facts

  • Infostealer malware was used to harvest active session tokens from affected users' devices.
  • Stolen tokens allowed attackers to access Claude accounts without passwords or MFA.
  • Anthropic responded by locking out impacted accounts and invalidating compromised sessions.
  • The incident follows earlier reports of session hijacking targeting Claude users.
  • Users are advised to scan devices for malware and enable additional account security measures.

The lockouts appear to have been triggered by Anthropic's backend detection systems identifying anomalous session activity, such as logins from unexpected locations or devices. Affected users were signed out and, in some cases, required to verify their identity before regaining access. While disruptive, security researchers generally view this kind of rapid session invalidation as the correct response to confirmed token theft. The risk of doing nothing outweighs the inconvenience to legitimate users.

Infostealer infections are increasingly being used as the first step in account takeover chains targeting SaaS and AI platforms, with session cookies often sold on criminal marketplaces within hours of theft.Help Net Security
Claude AI Handboek by Leon Tindemans
Get the Claude AI Handboek
458 pages on getting more out of Claude, by AI expert Leon Tindemans. A printed book, written in Dutch, shipped worldwide with track and trace.
View the book →

A Recurring Security Challenge for Anthropic

This is not an isolated event. Threat actors have shown sustained interest in Claude user credentials. Earlier reporting flagged that fake Anthropic sites were being used to distribute infostealer malware targeting Claude Code users, suggesting organized campaigns rather than opportunistic attacks. The consistent focus on session tokens rather than passwords reflects how attackers adapt to platforms that enforce strong authentication. Stealing a live session is often easier than cracking a password.

Anthropic has not published a detailed post-mortem on this specific incident, but the forced lockout response mirrors steps taken after previous breaches. The company's ability to detect and act on suspicious session activity suggests its security monitoring has improved, though the volume of incidents points to an ongoing challenge. Users running Claude through API integrations or third-party tools face additional exposure, since credentials may be stored in environments with less rigorous security hygiene than Anthropic's own infrastructure.

For individual users, the practical advice remains consistent with any infostealer threat: scan devices with updated antimalware tools, rotate passwords after any suspected infection, and revoke API keys that may have been exposed. Checking active sessions in account settings and removing any unrecognized entries is also a recommended step. Session-based attacks are difficult to prevent entirely at the platform level because the initial infection happens on the user's own device, outside Anthropic's control.

The broader pattern of security incidents affecting Claude users underscores that AI platforms are now firmly in the target set for cybercriminals, not just enterprise software or financial services. As Claude's user base grows, the incentive for attackers to invest in credential harvesting campaigns grows with it. Anthropic's response in this case was swift, but the frequency of these events suggests both the company and its users will need to treat account security as an ongoing priority rather than a one-time setup.

Further reading: Learn more about Claude's model family, read our background on Anthropic, or browse the latest Claude AI news.