Anthropic forcibly logged out users suspected of malware infection, deleted their payment methods, and processed refunds.

Malware has been detected that hijacks users' PCs and misuses Anthropic's AI 'Claude.' Anthropic has detected this malware and is taking measures to forcibly log users out.
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/
Anthropic Warns Hackers Are Stealing Claude Sessions To Hijack Accounts
https://www.searchenginejournal.com/anthropic-warns-hackers-are-stealing-claude-sessions-to-hijack-accounts/587566/
This measure came to light when WorriedAssociate7029 shared an email from Anthropic on the online forum Reddit.
According to Anthropic, they discovered instances where malicious individuals were using data-stealing malware to hijack users' Claude login sessions and fraudulently consume their usage fees. Anthropic's system detected the fraudulent activity, and they took measures to forcibly log the affected users out of their Claude accounts, remove their payment methods, and refund the fees for the period deemed to be fraudulent.
Anthropic pointed out that this malware is common malware and unlikely to have been installed via Claude, but rather likely infected the user through other unofficial software. They warned that it probably copied browser cookies and authentication information from locally running software, and that Claude's login session was likely one of the stolen pieces of information.
Since the malware has already hijacked the browser that was logged into the Claude account, two-factor authentication performed during login will not prevent unauthorized use. In fact, WorriedAssociate7029 reported that two-factor authentication did not work for them.
WorriedAssociate7029 reported that he became infected after installing a pirated game. The golden rule is to never install suspicious software. According to WorriedAssociate7029, the malware also hijacked the user's social media accounts and repeatedly posted cryptocurrency scams and other fraudulent content.
Related Posts:







