What happened
- On August 30, 2026, Anthropic began notifying users whose active Claude sessions had been copied by malware installed on their own computers, according to BleepingComputer’s reporting based on the emails sent.
- An attacker picked out those sessions from the data the program had already been collecting and used them to consume the accounts’ balance.
- The company closed the compromised sessions, deleted saved payment methods and refunded the charges it identified as unauthorized.
- The programs involved are general-purpose: Vidar, Lumma, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of macOS machines. None has anything to do with Claude or was installed through it.
Why it matters
- The attack doesn’t touch the password or the second factor. It copies the session cookie, which already vouches for a valid login. Two-step verification doesn’t protect against this, and that’s where the common sense almost every team works with breaks down.
- It works for any service with an open session in the browser. The same technique that opens an AI account opens the one for email, the stock image library or the billing system. And an account opened by someone else inherits everything that assistant is allowed to read.
- The warning sign is administrative, not technical: usage that rises while nobody is working. On a small team sharing a paid account, that pattern is almost indistinguishable from someone else’s legitimate use. And that account may contain everything someone uploaded without reading the terms.
The number
6 malware families. Vidar, Lumma, StealC, RedLine, Acreed and Atomic Stealer. None was built to attack Claude. They collect everything they find, and someone later went looking for the sessions that were worth something.
Context
Anthropic was explicit on a point these notices usually leave out: closing the session invalidates what was stolen, “but it does not remove the malware.” If the machine is still infected, the next login can be captured just the same. That’s why the instruction to those affected was to clean the machine before saving a payment method again, not the other way around.
What’s next
- The company’s investigation remains open, and it warned that it may close sessions again if it detects similar signs. No timelines announced.
- Those affected must log in again and re-enter their payment method, once the machine has been disinfected.
- Subscriptions already paid for remain active until the end of the billing period.
Bottom line
The market for stolen sessions has been operating for years on email, banks and online stores. What’s new is that an AI subscription is now worth enough to appear in the same catalog.


