{"slug": "anthropic-warns-infostealers-are-hijacking-claude-sessions-and-draining-paid", "title": "Anthropic warns infostealers are hijacking Claude sessions and draining paid usage", "summary": "Anthropic warned that infostealer malware is stealing active Claude login sessions from infected Windows and Mac computers and using them to drain paid usage allowances, according to emails reviewed by BleepingComputer. Anthropic said it is revoking affected sessions, removing saved payment methods and refunding charges it identifies as unauthorized, and one Claude Max subscriber told TechCrunch his account kept consuming tokens while he was inactive before Anthropic suspended the account, invalidated sessions and issued a partial refund. Anthropic has not disclosed how many accounts were affected or the campaign's duration, and the evidence points to endpoint infections rather than a confirmed breach of Anthropic's systems.", "body_md": "# Anthropic warns infostealers are hijacking Claude sessions and draining paid usage\n\n- Anthropic says infostealers are stealing active Claude sessions and using them to consume account allowances. <sup>[\\[1\\]](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/)</sup>\n- The likely exposure is on infected Windows or Mac computers, where malware can copy browser sessions without requiring a fresh password or two-factor-authentication login. <sup>[\\[2\\]](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/)</sup>\n- Anthropic says it is revoking sessions, removing saved payment methods and refunding charges it identifies as unauthorized; users should remove malware before signing in again. <sup>[\\[2\\]](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/)</sup>\n\nAnthropic has warned some Claude users that infostealer malware is stealing active login sessions from their computers and using them to burn through paid usage allowances. The company began notifying affected customers after detecting suspicious activity, according to emails reviewed by BleepingComputer. [\\[1\\]](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/)\n\nThe reports so far involve paid Claude accounts, including users with high usage limits and Claude Code access. One Claude Max subscriber told TechCrunch that his account continued consuming tokens while he was inactive; Anthropic later suspended the account, invalidated sessions and issued a partial refund. [\\[3\\]](https://techcrunch.com/2026/09/08/hackers-are-stealing-claude-tokens-from-subscribers/)\n\n## The exposure starts on the device\n\nThe available evidence points to endpoint infections rather than a confirmed breach of Anthropic’s systems. Commodity infostealers can collect browser cookies and authenticated sessions alongside passwords and other locally stored credentials. That lets an attacker reuse an active Claude session without repeating the normal sign-in flow, which can limit the protection provided by password changes or multifactor authentication after the session has already been copied. Independent security coverage has described the same session-hijacking pattern. [\\[2\\]](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/)[\\[4\\]](https://www.securityweek.com/anthropic-warns-claude-users-of-infostealer-malware-infections/)\n\nAnthropic has not disclosed how many accounts were affected, the campaign’s duration or whether all reported cases share the same malware source.\n\n## What users can do\n\nAnthropic says it is signing out affected users, removing saved payment methods and refunding charges it determines were unauthorized. Users who suspect misuse should log out of all active Claude sessions through the web account settings, revoke Claude Code authorizations, change relevant credentials and investigate or rebuild an infected device before logging in again. Anthropic’s help center documents the account-wide logout process. [\\[1\\]](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/)[\\[5\\]](https://support.anthropic.com/en/articles/10310342-how-do-i-log-out-of-all-active-sessions)\n\n## Companies mentioned\n\n## Further sources\n\nThe stories that matter, in one email. Free — unsubscribe anytime.", "url": "https://wpnews.pro/news/anthropic-warns-infostealers-are-hijacking-claude-sessions-and-draining-paid", "canonical_source": "https://mlq.ai/news/anthropic-warns-infostealers-are-hijacking-claude-sessions-and-draining-paid-usage/", "published_at": "2026-09-10 14:47:58.402918+00:00", "updated_at": "2026-09-10 14:47:59.895170+00:00", "lang": "en", "topics": ["ai-products", "ai-tools"], "entities": ["Anthropic", "Claude", "Claude Code", "Claude Max", "BleepingComputer", "TechCrunch"], "alternates": {"html": "https://wpnews.pro/news/anthropic-warns-infostealers-are-hijacking-claude-sessions-and-draining-paid", "markdown": "https://wpnews.pro/news/anthropic-warns-infostealers-are-hijacking-claude-sessions-and-draining-paid.md", "text": "https://wpnews.pro/news/anthropic-warns-infostealers-are-hijacking-claude-sessions-and-draining-paid.txt", "jsonld": "https://wpnews.pro/news/anthropic-warns-infostealers-are-hijacking-claude-sessions-and-draining-paid.jsonld"}}