← Back to news

Anthropic locks out Claude users after infostealers hijack login sessions

Help Net Security31/08/2026, 11:30
Read full article →

Summary

AI-Generated

Key Points:

  • Infostealer malware, including families such as Vidar, Lumma, StealC, RedLine, and Atomic Stealer, has compromised user login sessions for Anthropic's Claude accounts.
  • The impact includes unauthorized access to user accounts, potential financial fraud through saved payment methods, and the risk of session hijacking that bypasses two-factor authentication.
  • Recommended actions for affected users include scanning for and removing malware, changing passwords, enabling 2FA on email accounts, updating browser-stored passwords, and invalidating active sessions across other services.

Technical Details: The infostealer malware typically arrives via unofficial downloads or malicious applications and captures saved passwords and session cookies from browsers. This allows attackers to impersonate users without needing to bypass 2FA.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Defense Evasion)
  • T1003.001 - OS Credential Dumping: Credentials from Web Browsers (Credential Access)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.