Claude Sessions Stolen to Burn Paid Usage

Anthropic warned that infostealer malware on compromised PCs has been stealing active Claude login sessions and using them to access accounts and burn through paid usage. The issue is session theft, not password guessing: the attacker gets a live browser session and can enter Claude as the user without logging in again. That means the browser token is the asset, not just the password. If the infected machine still holds a valid session, resetting credentials may not end the misuse because the attacker can keep using the already-authenticated session until it expires or is removed. For anyone running Claude on a managed or personal endpoint, the exposure sits at the device and browser layer rather than inside Anthropic's service. The same pattern applies to other SaaS products that stay signed in in the browser: a local infostealer can turn one infected PC into ongoing metered abuse.

Part of the PlainSec briefing for 2026-08-31

Editions

Sources