Your Claude Account Can Be Hijacked Without Your Password: What to Do Now
Infostealer malware is stealing Claude session cookies and draining AI subscriptions without touching your password or 2FA code.
Your Password Was Never the Problem
Passwords protect the door. But once you walk through and log in, your browser holds something more valuable: a session cookie. It's a small file that tells every website you visit "yes, this person already proved who they are, let them in." No password required. No verification code. Just the cookie.
In late August 2026, Anthropic notified affected Claude users that attackers had stolen exactly those cookies. The malware didn't break into Claude. It broke into the computers of people who use Claude. From there, it grabbed the sessions those people already had open and handed them to criminals.
That distinction matters. The breach didn't happen at Anthropic's servers. It happened on ordinary laptops and desktops, one sketchy download at a time.
How Does Session Hijacking Actually Work?
When you log into Claude, your browser receives a session cookie, a kind of temporary all-access pass. Stealing that cookie is the same as stealing your logged-in state. Whoever holds it can use Claude as you, spend your usage credits as you, and charge your payment method as you. They don't need your email. They don't need your password. They don't need to beat your two-factor authentication. The cookie already cleared all of that.
Infostealer malware is built for exactly this. It runs quietly in the background, hooking into your browser's storage and scooping up every session token it finds, Claude, Google, GitHub, your bank, all of it. Then it ships those tokens to whoever is running the campaign.
The malware families confirmed in this campaign: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on a smaller number of Macs.
These are not exotic nation-state tools. They are commodity malware, cheap to rent, easy to deploy, and effective.
How Did People Get Infected?
The malware arrived through unofficial software downloads and malicious apps, not through anything Claude itself did. A cracked app. A fake plugin. A "free" tool that sounded too useful to pass up.
Any computer with an active Claude session becomes a target the moment something malicious runs on it. It doesn't matter how strong your password is. It doesn't matter whether you use two-factor authentication. If the machine is compromised, the session is exposed.
What Did Attackers Do Once Inside?
They burned usage limits. They triggered charges on stored payment methods. A hijacked Claude account isn't just an identity problem, it's a financial one.
Anthropic responded by force-signing out all compromised sessions, deleting the saved payment methods on affected accounts, and refunding the unauthorized charges it identified. That's a meaningful response, and it stopped the bleeding. But the underlying access still happened.
What to Do Right Now
These steps take less than 30 minutes combined. Do them today.
-
Sign out of all Claude sessions. Go to your account settings and revoke all active sessions. This kills any stolen cookies that might still be valid. Do this from a device you trust.
-
Remove stored payment methods. If attackers can't charge a card on file, they can't drain it. Remove your card from Claude and any other AI tool you use regularly. Re-add it only when you need it.
-
Check your other accounts. Infostealers don't stop at Claude. The same malware that grabbed your Claude cookie likely grabbed cookies for everything else you had open. Audit your Google, GitHub, and email sessions and revoke anything you don't recognize.
-
Scan your machine. Run a reputable antivirus or antimalware scan. Windows Defender is free and genuinely capable. Malwarebytes has a free tier. Mac users: Malwarebytes for Mac covers AMOS and similar families. If you find an infection, run the scan from a clean device if possible and consider a full OS reinstall for the infected one.
-
Stop downloading from unofficial sources. Cracked software is the primary delivery vector for these malware families. No free Photoshop is worth handing an attacker your sessions.
-
Enable passkeys where available. Passkeys are phishing-resistant and can't be intercepted the way passwords can. They don't prevent session theft after login, but they make the initial compromise harder. Anthropic supports passkeys, set one up.
-
Review charges on your payment methods. Look for small or unfamiliar charges from the past few weeks. Dispute anything you didn't authorize. If Anthropic refunded charges you weren't aware of, check your statement anyway, infostealers don't limit themselves to one service.
One More Layer: Your Devices Are the Perimeter Now
Here's the systemic truth underneath this incident: the security boundary for AI tools is no longer a login screen. It's your physical devices.
Every service you use assumes the machine running your browser is yours and is clean. That assumption breaks completely the moment malware runs. No password policy, no 2FA requirement, and no company-side security measure can compensate for a compromised endpoint. The responsibility sits with whoever owns the machine.
That's not a criticism of Anthropic or of users who got hit. It's a structural reality of how the web works, and it applies to every AI tool, every SaaS product, and every account you hold.
The companies building these tools can force-logout sessions and refund charges after the fact. Only you can stop the malware from running in the first place.
Do this now:
- Revoke all active Claude sessions from account settings
- Remove stored payment methods from Claude and other AI tools
- Scan your machine with Windows Defender or Malwarebytes
- Check your payment statements for unauthorized charges
- Stop downloading software from unofficial sources
- Enable passkeys on any account that supports them
Sources
Common Questions About AI Threats
What is AI voice cloning and how are criminals using it?
AI voice cloning can replicate a person's voice from as little as three seconds of audio. Criminals use it to impersonate family members in fake emergency calls, executives requesting wire transfers, or officials demanding payment. Always verify urgent calls by hanging up and calling back on a known number.
How can I tell if a video is a deepfake?
Look for unnatural blinking, blurry edges around the hairline, audio that mismatches lip movements, and inconsistent lighting between face and background. Tools like Deepware Scanner can help detect deepfakes.
Are AI-powered phishing emails harder to detect?
Yes. AI generates grammatically perfect, personalized phishing emails using details scraped from LinkedIn or social media. Verify unexpected requests involving money or passwords by calling the sender directly on a known number.
More in ai threats
Stay invisible. Follow @hack_decoded
