Anthropic has notified users of its Claude AI platform that a number of accounts have been compromised through infostealer malware infections, according to a report from SecurityWeek. The company is warning users who may have had their credentials or session tokens stolen to take immediate steps to secure their devices and accounts before further damage occurs.
What Is Happening and Who Is at Risk
Infostealer malware is designed to silently harvest credentials, browser session cookies, and authentication tokens from infected machines. Once attackers obtain a valid session token, they can access a victim's Claude account without needing a password at all. This type of attack does not require any vulnerability in Claude itself. The weak point is the user's own device. Infostealer malware has previously been observed hijacking Claude sessions to drain usage quotas, suggesting this is part of a broader and ongoing pattern of abuse targeting AI platform users.
Key Facts
- Infostealer malware harvests session tokens, allowing account takeover without passwords
- Anthropic proactively notified affected users rather than waiting for reports
- The malware targets the user's device, not Claude's infrastructure directly
- Users are advised to scan devices, revoke active sessions, and reset credentials
- This follows a pattern of threat actors specifically targeting AI platform users
The scope of the current incident has not been fully detailed publicly, but Anthropic's decision to issue direct warnings signals that the company has identified a meaningful number of affected accounts. Security researchers have noted that AI platforms are increasingly attractive targets given users often store sensitive work, API keys, and proprietary data within their chat histories. Earlier concerns about Claude user data exposure have already raised the profile of account security among the platform's user base.
Infostealer campaigns targeting AI platforms are accelerating because the accounts hold high value for both resale and direct exploitation. A compromised Claude account can be monetized in multiple ways almost immediately.Security researcher commentary, SecurityWeek
How Attackers Are Gaining Access
The infection chain typically begins far from Anthropic's own systems. Users may encounter infostealer payloads through phishing emails, malicious software downloads, or compromised websites. Fake Anthropic websites have previously been used to distribute infostealer malware to Claude Code users, demonstrating that threat actors are willing to build convincing infrastructure specifically to target this user base. Once installed on a device, the malware quietly exfiltrates stored credentials and active browser sessions to attacker-controlled servers.
Anthropic's response reflects a broader shift in how AI companies are approaching user security. Rather than treating account compromises as purely a user responsibility, Anthropic appears to be monitoring for anomalous access patterns and proactively reaching out when it detects signs that an account may have been taken over. Users who receive a warning from the company are advised to run a full malware scan on any device used to access Claude, revoke all active sessions through their account settings, rotate their passwords, and review whether any API keys associated with their account need to be regenerated.
Steps Users Should Take Now
Security professionals recommend treating any Anthropic notification about potential compromise as urgent. Infostealer infections often go undetected for extended periods, meaning attackers may have had access to an account for days or weeks before a warning is issued. Users should also examine whether the same credentials were reused on other platforms, as infostealer logs are frequently sold in bulk and used across multiple services simultaneously.
The incident is a reminder that security hygiene around AI tools matters as much as it does with any other online service. Enabling multi-factor authentication where available, keeping operating systems and browsers updated, and avoiding software downloads from unverified sources all reduce exposure to this class of attack. As Claude continues to grow as a platform for professional and enterprise use, the value of its user accounts as targets is only likely to increase, and threat actors are clearly paying attention.