CYBERSECURITY

Anthropic Warns Hackers Are Stealing Claude Sessions to Hijack Accounts

Anthropic Warns Hackers Are Stealing Claude Sessions to Hijack Accounts

How Attackers Exploit Active Sessions Without Passwords

Anthropic has issued a warning that cybercriminals are using infostealer malware to hijack user accounts on its Claude AI platform by stealing active login sessions. The attack allows unauthorized access without needing passwords, enabling attackers to consume account credits and usage quotas. The company confirmed the threat targets individual and organizational users who remain logged into Claude via web browsers or desktop applications. Security teams observed the activity in recent weeks as part of broader monitoring of credential theft campaigns.

The method relies on malware that extracts session tokens from infected devices, which attackers then replay to impersonate legitimate users. Unlike traditional credential theft, this approach bypasses multi-factor authentication because it uses valid, active sessions rather than passwords. Anthropic explained that stolen sessions grant full access to the account’s API usage, chat history, and settings until the session expires or is revoked. The company noted that the malware often spreads through phishing emails or compromised software downloads, emphasizing that no vulnerability in Claude’s systems was exploited.

What Steps Can Users Take to Protect Their Claude Accounts?

Once malware infects a device, it scans for stored session data from browsers or apps where users are logged into Claude. These tokens are uploaded to attacker-controlled servers and used to initiate requests that appear as legitimate user activity. Anthropic’s security team observed patterns where stolen sessions were used to run high-volume API calls, rapidly depleting credits allocated to accounts. The firm stated that affected users may notice unexpected usage spikes or inability to access their accounts due to quota exhaustion. Anthropic is working with threat intelligence partners to identify malware families involved and block known malicious endpoints.

Anthropic advises users to log out of Claude after each session, especially on shared or public devices, and to avoid saving login credentials in browsers. The company recommends enabling device-level security measures such as updated antivirus software and avoiding downloads from untrusted sources. Users who suspect compromise should immediately revoke all active sessions through their account settings and rotate API keys if applicable. Anthropic confirmed it is improving session security by shortening token lifespans and enhancing anomaly detection for unusual usage patterns. The firm stressed that vigilance remains critical as infostealer tactics continue to evolve.

How do attackers use stolen sessions to drain Claude accounts? They replay active session tokens to make API requests that consume credits, often running automated tasks until quotas are exhausted.

Frequently Asked Questions

Can multi-factor authentication prevent this type of attack? No, because the attack uses valid session tokens that bypass login prompts entirely, rendering MFA ineffective once the session is active.

What should I do if I suspect my Claude account was compromised? Log out of all sessions immediately, check usage logs for anomalies, and run a full antivirus scan on your devices.

Content written by Hannah Osei for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment