Claude Accounts Hijacked via Infostealer Malware That Bypassed 2FA
Anthropic has confirmed that multiple Claude user accounts were compromised through infostealer malware installed on users' own devices, not through a breach of Anthropic's systems. Malware variants including Vidar, LummaC2, and Atomic Stealer stole active browser session cookies, allowing attackers to access accounts without needing passwords or triggering two-factor authentication. Because session cookies represent an already-authenticated state, they bypass the login step that 2FA is designed to protect. Attackers exploited the stolen sessions to consume paid usage credits before being detected. Anthropic responded by terminating the compromised sessions, removing saved payment methods, and refunding unauthorized charges.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in