Infostealer malware is being used to hijack active Claude browser sessions, highlighting a growing cybersecurity threat to premium AI accounts.
Cybercriminals have found a new way to exploit paid artificial intelligence accounts, and the attack highlights a security weakness that extends far beyond AI.
Anthropic is warning some Claude users that infostealer malware has stolen active browser sessions from infected computers. Attackers can then use those sessions to enter victims’ Claude accounts and consume their paid AI usage — potentially without ever entering the victim’s password or two-factor authentication code.
The important distinction: there is currently no evidence that hackers breached Claude itself.
Instead, the attackers appear to be compromising users’ devices and stealing the digital credentials browsers use to remember that someone has already successfully logged in.
That makes this much bigger than a Claude story.
It is another reminder that in an increasingly cloud-based world, criminals don’t necessarily need your password if they can steal the authenticated session that comes after it.
What Is Happening to Claude Accounts?
According to reports based on notifications Anthropic sent to affected customers, criminals are using common “infostealer” malware to harvest active Claude login sessions from users’ computers.
Those stolen sessions can then be replayed by an attacker, effectively allowing the criminal to impersonate an already-authenticated user.
That is fundamentally different from a traditional password attack.
Normally, an attacker might steal your username and password, attempt to log in and then encounter another security barrier such as two-factor authentication.
With session theft, the attacker may instead steal the browser data that essentially tells the service:
This user already authenticated.
The criminal can potentially reuse that session without repeating the normal login process.
Why Two-Factor Authentication May Not Stop It
Two-factor authentication remains an extremely important security tool. However, this attack demonstrates one of its limitations.
2FA protects the authentication process.
A stolen authenticated session can potentially allow an attacker to avoid that process entirely.
Malwarebytes reports that infostealers can steal browser sessions and session cookies, enabling attackers to bypass conventional credentials and MFA protections.
Think of your password and 2FA code as security guards checking identification at the entrance to a building.
A valid browser session is more like the badge you receive after you’ve already entered.
If someone steals the badge, they may not need to go through the front door again.
Why Hackers Want Claude Accounts
The apparent objective is surprisingly straightforward: AI computing power costs money.
Paid Claude accounts provide access to higher usage levels and, depending on account settings, additional consumption-based usage.
An attacker who hijacks someone else’s account can therefore use Claude while making the victim’s account absorb the usage.
Malwarebytes reports that some paid Claude users can purchase additional usage credits once their normal limits have been reached. Users may also configure automatic credit reloads, potentially increasing the financial exposure of a compromised account.
In other words, AI usage itself has become something worth stealing.
That creates a new economic incentive for cybercriminals.
Anthropic Is Signing Out Affected Users
Anthropic has reportedly taken several steps after detecting the suspicious activity.
The company has signed affected users out of Claude, removed stored payment methods and refunded charges it identified as unauthorized.
Anthropic also reportedly told affected customers that it had no reason to believe the malware originated from Claude or resulted from something users did inside Claude.
That’s an important distinction.
This appears to be an endpoint malware problem, not evidence that attackers penetrated Anthropic’s central systems and extracted everyone’s Claude credentials.
Infostealers Are Becoming a Major Cybersecurity Problem
Infostealer malware is designed to quietly collect valuable information from an infected device.
Depending on the malware, that can include saved passwords, browser cookies, authentication tokens, cryptocurrency wallet information and other credentials.
The Claude incident demonstrates why session tokens are particularly valuable.
Modern life increasingly happens inside persistent browser sessions.
People remain signed into email, banking platforms, social networks, cloud storage, corporate applications and AI services for days or weeks.
That convenience creates another target.
If malware can steal the information proving that you’re already authenticated, compromising your password becomes less important.
AI Accounts Are Becoming Valuable Digital Assets
There is another significant takeaway from this incident.
Premium AI accounts now have measurable economic value.
AI subscriptions provide access to expensive computing infrastructure. Advanced models can perform coding, research, analysis, content generation and increasingly autonomous tasks.
Criminals therefore have a financial incentive to steal access.
We’ve seen similar economics elsewhere in technology.
Hackers steal cryptocurrency wallets because they contain money. They hijack cloud servers to mine cryptocurrency. They steal streaming credentials because subscriptions have resale value.
Now premium AI capacity belongs on that list.
As AI models become more powerful — and more expensive to operate — stolen access could become increasingly attractive.
What Claude Users Should Do
Users who believe their account or computer may have been compromised should treat the underlying device as the primary concern.
Changing a Claude password alone may not solve an infection if malware remains on the computer.
Users should consider scanning their devices with reputable security software, removing suspicious applications or browser extensions, reviewing active sessions and signing out unfamiliar devices.
Passwords for sensitive accounts should be changed from a clean device if an infostealer infection is suspected.
Users should also review Claude usage and billing activity for anything they don’t recognize.
Anyone who received a security notification directly from Anthropic should follow the company’s instructions.
This Isn’t Just About Claude
Perhaps the biggest lesson from this incident is that browser sessions themselves have become high-value credentials.
Companies have spent years encouraging stronger passwords and two-factor authentication, and both remain essential.
But cybersecurity is evolving.
The next generation of account theft may increasingly focus on stealing what happens after you successfully authenticate.
AI platforms are particularly attractive because stolen access provides criminals with something immediately useful: expensive computing resources someone else is paying for.
For consumers and businesses, that changes the security equation.
Protecting your password is no longer enough.
Protecting the device holding your authenticated sessions matters just as much.
And as AI becomes embedded deeper into email, corporate systems, coding environments, financial workflows and personal data, the value of those sessions is only likely to grow.
This Newsroom Take: The Claude incident isn’t evidence that Claude itself was hacked. It’s a warning about something potentially more consequential: our browser sessions are becoming digital keys to increasingly valuable services. In the AI era, hackers don’t always need to steal your password. Sometimes they just need to steal the proof that you already entered it.