Anthropic has signed out a subset of Claude users, removed their saved payment methods, and issued refunds after infostealer malware on affected PCs hijacked active login sessions and drained usage credits1.
The company warned affected customers that information-stealing trojans on their personal computers had captured active Claude session tokens2. Attackers then used those stolen sessions to run unauthorized Claude queries, consuming paid usage.
To contain the damage, Anthropic is logging compromised customers out of their accounts and stripping stored payment data to block further unauthorized consumption3. The company is also processing refunds for usage attributable to the hijacked sessions.
The incident is notable because the compromise vector sits outside Anthropic's own infrastructure. Infostealer malware, which typically harvests browser cookies, session tokens, and credentials from infected endpoints, enabled attackers to impersonate legitimate users without breaching Anthropic's servers directly.
ANALYSIS The response pattern, forced logouts combined with payment-method removal, treats the problem as an ongoing exposure rather than a contained breach: as long as stolen session tokens remain valid and payment instruments are on file, attackers can continue to rack up charges.
The episode arrives days after Vector Wire covered a separate AI-security incident in which a ransomware affiliate used the Cursor AI coding agent to breach at least seven companies ctx. Together, the two events illustrate distinct but converging threat surfaces: one where AI tools are weaponized by attackers, and another where AI platforms themselves become targets of conventional credential-theft techniques.
ANALYSIS For enterprise buyers evaluating AI-platform risk, the Anthropic case underscores that endpoint hygiene, not just vendor-side controls, determines exposure. Session-token theft bypasses multi-factor authentication after the initial login, making post-authentication token management a critical control point.
Anthropic's public communications, as reported by BleepingComputer's Mayank Parmar and SecurityWeek, frame the action as protective rather than reactive to a breach of Anthropic's own systems.