Anthropic signed affected people out of Claude after stolen Claude sessions showed up on their accounts. The company emailed those users that infostealer malware copied login sessions from their own computers. Attackers then used those sessions to burn Claude usage. Anthropic says it also removed the saved payment method and refunded charges it tied to the misuse.
The email does not describe an Anthropic data-center breach. Instead, the company points at malware already on Windows PCs, plus a small number of Macs. Anthropic says phones and tablets were not part of this. It also says it has no reason to believe the malware came from Claude, arrived through Claude, or tied to anything the owner did inside Claude.
Session cookies beat the login screen
Infostealers copy more than passwords. They grab browser cookies that prove a user is already signed in. Then an attacker can replay that cookie and land inside Claude without a password prompt or a 2FA check. Specifically, Anthropic told affected users that if usage limits looked like they refilled and then drained while they were not using Claude, that pattern was likely the cause.
The families named in the email so far are Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on a small number of Macs. Those tools are general-purpose stealers. They typically arrive with an unofficial download or a malicious app. Meanwhile a Claude session is just one of the things they collect.
A forced sign-out is only step one
Anthropic’s immediate move is to kill the stolen session. Signing someone out everywhere is how that works. Removing the card on file stops extra usage charges through Claude. However, Anthropic is blunt about the limit: Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware.
As a result, logging back in on a still-infected PC can mint a fresh cookie for the same attacker. Anthropic told affected users to clean the machine first. Then it pointed them at a new password and 2FA on the email address tied to Claude, and only after that at putting a payment method back on the account. It also said it may sign the account out again if similar misuse shows up.

How Claude says to check remaining sessions
Anthropic still has no public newsroom post on this campaign. Its Help Center does document the account controls. From Settings, then Account, Claude lists active sessions with device, browser, approximate location, and last activity. Owners can terminate unfamiliar rows from that list. A separate help article covers logging out of every session at once, including web, desktop, and mobile.
Still, those pages are not antivirus. They only revoke Claude’s own tokens. Also, the web app’s documented session length is 28 days of inactivity, with hourly refresh while someone is actually using claude.ai. In addition, similar session-hygiene questions now sit next to other AI-account defenses, including OpenAI’s Lockdown Mode and the broader Claude surface around Claude Cowork. Besides the email, Anthropic has not published a count of affected accounts.












































