www.darkreading.com 8/31/2026, 9:41:16 PM · external

Anthropic Users Hit by Infostealer Attacks, Session Thefts

Anthropic Users Hit by Infostealer Attacks, Session Thefts
CyberSIXT Evidence Panel Source marked as original reporting

ANTHROPIC experienced a security incident where threat actors stole session information from multiple users through infostealer malware. Affected users were proactively logged out of their Claude accounts and their saved payment methods were removed. The attackers used various infostealers like Vidar and RedLine, likely installed via malicious apps. This incident highlights a shift from password theft to targeting session cookies, complicating incident response and making it harder to secure accounts even with MFA.

Anthropic has cautioned users to remove the infostealer malware from their systems and update their credentials to prevent future breaches.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline