Most popular now
Advertisement

Anthropic halts the use of hijacked Claude sessions and refunds stolen money

Money refunded, hijacked Claude sessions
Антропні дослідження зупинили використання сесій Claude, які були захоплені, та повернули вкрадені кошти. Photo: НВ — Техно

According to НВ — Техно: On September 4 at 12:02, Anthropic announced the forced termination of compromised Claude sessions. The reason was the discovery of session cookie theft through malware info stealers. In response, the company deleted saved payment cards and refunded the money that had been spent by the attackers.

Details of the incident with Claude sessions

Attackers gained access to active Claude sessions, so they did not need to re-enter their password or two-factor authentication code. Six families of malware were used to steal sessions. On Windows, Vidar, Lumma, StealC, RedLine, and Acreed were recorded, while on macOS, there were isolated cases of Atomic Stealer (AMOS) being used. These info stealers were not specifically created to target Claude.

Anthropic found no signs of a breach in its own infrastructure. However, researchers from CrowdStrike and Palo Alto Networks report the trade of access to Claude, ChatGPT, and Gemini accounts. Stolen data may be used through proxy services that offer access to AI platforms at a lower cost than an official subscription. The exact number of affected users has not been disclosed by the company. Nevertheless, Anthropic emphasizes that terminating hijacked sessions does not eliminate the info stealers from devices.

Recommendations from Anthropic for protection

In light of the incident, Anthropic advises users to:

  • remove malware from their devices;
  • change passwords for email linked to accounts;
  • enable two-factor authentication;
  • add payment details back only after completing these steps.

These measures will help reduce the risk of further malicious actions.

The situation highlights that as the activity of attackers grows, cybersecurity concerns not only individual users but entire platforms. For the Russian-speaking audience, this is an additional signal to check devices for info stealers and strengthen account protection, especially if access to AI services is used regularly.

Advertisement

Read also

Advertisement

Advertisement

Advertisement