Anthropic Signs Out Claude Users After Infostealer Session Thefts

September 02, 2026
Anthropic signed out affected Claude users and removed saved payment methods after infostealer malware stole login sessions and allowed account access.
Anthropic Signs Out Claude Users After Infostealer Session Thefts

Anthropic signed an unknown number of Claude users out of their accounts after a threat actor used infostealer malware to steal login sessions and access paid usage, Dark Reading reports.

The company told affected users that the malware was on their own systems and was not related to Claude. Anthropic said the campaign involved Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer on a small number of Macs.

Anthropic removed saved payment methods from affected accounts and said it refunded unauthorized charges where attackers had used a payment card for Claude usage. Signing users out invalidated the stolen sessions used to access the accounts.

The company advised affected users to remove the malware before signing back in, then secure the email account used for Claude by changing the password, signing out other devices, and enabling 2FA. It also told users to update other saved browser passwords before adding a payment method back to Claude.

We hope you enjoyed this article.

Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.

Also, consider following us on social media:

Subscribe to Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.

Trend report

Cybersecurity Trends Report 2025

Netwrix

The Cybersecurity Trends Report 2025 by Netwrix Research Lab provides insights into how organizations are adapting their cybersecurity strategies amidst growing AI adoption. The report, based on a survey of 2,150 IT professionals from 121 countries, highlights key trends such as the increase in hybrid IT environments, AI-driven security challenges, and the rising costs of security incidents.

Read more