Anthropic is sending security warnings to some Claude users after finding that attackers have been stealing active Claude login sessions from malware-infected computers and then using those sessions to access accounts and consume user quotas.
Users on Reddit have posted screenshots of warning emails from Anthropic. The company described the issue as session theft rather than a direct password compromise.
Attackers are taking authenticated browser sessions
According to one user, what was stolen was not the account password but an already authenticated browser session. That included browser cookies and the session ID.
With that login state in hand, an attacker can impersonate the user without entering the password again or completing 2FA. The user said they had signed in with Google and had two-factor authentication enabled, but their browser cookie and session ID were still taken.
Anthropic named multiple infostealers in its warning
In the email, Anthropic listed several infostealer families tied to this kind of activity: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, along with Atomic Stealer, or AMOS, on Mac.
These malware strains are built to steal browser cookies, passwords and related data. Anthropic said the problem is not a security vulnerability in Claude itself.
Suspicious sessions were revoked and payment methods removed
The same user said in replies to other Reddit users that they had previously downloaded pirated software. Anthropic said in its email that it had revoked detected suspicious login sessions, removed saved payment methods from the account, and handled related unauthorized charges.
The company also warned that changing a password alone is not enough. If the malware remains on the computer, newly created login sessions can still be stolen again.

