Infostealer Campaign Targets Anthropic Claude Users, Enables Session Theft
Threat actors deploy information-stealing malware to hijack active sessions and gain unauthorized access to Claude accounts.

Key Takeaways
- Infostealer malware is being used to harvest session tokens from Anthropic Claude users.
- Attackers can hijack active accounts without needing passwords, enabling unauthorized access.
- The campaign has a global scope, but the exact number of victims is unknown.
- Anthropic's platform was not breached; attacks target user endpoints and sessions.
- Users are advised to rotate credentials, enable MFA, and monitor for suspicious activity.
Quick answers
- What happened?
- A threat actor has been using various infostealer malware variants to collect session information from Anthropic Claude users. The stolen session data is being used to hijack active accounts without requiring passwords, affecting an unspecified number of users globally. Anthropic has not reported a platform breach, but the attacks leverage stolen credentials and tokens to bypass authentication.
- Which products are affected?
- Claude
- What should defenders do?
- Users should rotate credentials, enable multi-factor authentication where available, and monitor account activity for signs of unauthorized access. Organizations should educate users on phishing and malicious download risks.
According to a report published by Dark Reading on August 31, 2026, a threat actor has been deploying infostealer malware to target users of Anthropic's Claude AI platform. The malware is designed to harvest session tokens, browser cookies, and other credentials from infected systems. With these stolen session artifacts, the attacker can gain unauthorized access to Claude accounts without needing the user's password, effectively performing account takeover through session hijacking.
The exact number of affected users remains unspecified, and the report indicates the campaign is active with a global scope. The infostealers were likely distributed through common vectors such as phishing, malicious downloads, or compromised websites. Anthropic's infrastructure itself was not compromised; rather, the attacks target the users' local environments and active sessions.
Security researchers note that infostealers have become a prevalent method for threat actors to obtain persistent access to cloud and AI services. By capturing session tokens, attackers can maintain access even if the user changes their password, unless the compromised sessions are invalidated. The report advises users to remain vigilant and follow credential hygiene practices.
Security Details
Infostealers harvested session tokens and browser credentials from user endpoints. These tokens were used to hijack active Claude accounts without password authentication.
Affected products
Claude
Mitigation
Users should rotate credentials, enable multi-factor authentication where available, and monitor account activity for signs of unauthorized access. Organizations should educate users on phishing and malicious download risks.
Sources
Dark reading
Anthropic Users Hit by Infostealer Attacks, Session Thefts
Aug 31, 2026 · 21:08
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




