{"id":756331,"date":"2026-09-01T05:02:18","date_gmt":"2026-09-01T05:02:18","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/756331\/"},"modified":"2026-09-01T05:02:18","modified_gmt":"2026-09-01T05:02:18","slug":"anthropic-cracks-down-on-hijacked-user-accounts-mining-ai-tokens","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/756331\/","title":{"rendered":"Anthropic cracks down on hijacked user accounts mining AI tokens"},"content":{"rendered":"<p class=\"kicker \" style=\"\">security<\/p>\n<p class=\"subtitle \" style=\"\">Commodity malware steals authenticated sessions, letting thieves freeload on victims&#8217; paid usage<\/p>\n<p>Rather than paying for their own Claude usage, crims are using malware to steal access to other people&#8217;s accounts. Aware of this issue, Anthropic has signed at least one affected user out and removed the saved payment method to stop stolen sessions being abused. <\/p>\n<p>According to an email shared by Reddit user WorriedAssociate7029, who sent a copy to The Register, Anthropic has been keeping an eye on a threat actor using infostealer malware to hijack Claude login details, session cookies, and other info needed to subvert multifactor authentication on user accounts. Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves.<\/p>\n<p>Fortunately for WorriedAssociate7029, Anthropic logged the user out of their account and deleted their stored payment method because it had detected evidence of attempted fraud.\u00a0<\/p>\n<p>\u201cA few days ago, my social media accounts were hacked,\u201d WorriedAssociate said, adding that they&#8217;d managed to track the malware down with the help of Claude Opus 5 Max and, they believe, cleaned the system. \u201cBut last night I received this email from Anthropic warning me of an attempt to steal tokens via the API.\u201d<\/p>\n<p>They explained that the attempt failed, apparently thanks to Anthropic spotting it, but they realized that meant that the cybercriminal behind the incident seemed to have hijacked Google account credentials, cookies, and session IDs as well, since that\u2019s how they were signed into Claude. After changing their password again and removing all active sessions, it appears they are now safe.<\/p>\n<p>Who\u2019s eating your cookies?<\/p>\n<p>Anthropic made clear in the email that the credential theft wave it\u2019s identified has nothing to do with Claude itself, nor is it some sort of fancy, new-fangled, agentic AI malware that\u2019s being used to create a base of accounts for bad actors to abuse. This is just good old-fashioned infostealer malware being turned to a new purpose, the email explains.\u00a0<\/p>\n<p>\u201cWe have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,\u201d the email forwarded to us by WorriedAssociate and posted to Reddit stated. \u201cYour Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them.\u201d\u00a0<\/p>\n<p>In this case, it\u2019s well-known infostealing malware too: <a href=\"https:\/\/www.theregister.com\/security\/2022\/09\/22\/fake-sites-fool-zoom-users-into-downloading-deadly-code\/1186061\" rel=\"nofollow noopener\" target=\"_blank\">Vidar<\/a>, <a href=\"https:\/\/www.theregister.com\/security\/2025\/08\/04\/python-powered-malware-grabs-200k-passwords-credit-cards\/693950\" rel=\"nofollow noopener\" target=\"_blank\">LummaC2<\/a>, <a href=\"https:\/\/www.theregister.com\/security\/2026\/06\/24\/microsoft-uses-ai-to-link-two-malware-operations-in-racketeering-suit\/5261656\" rel=\"nofollow noopener\" target=\"_blank\">StealC<\/a>, <a href=\"https:\/\/www.theregister.com\/security\/2024\/10\/29\/feds-name-a-russian-accused-of-developing-redline\/559082\" rel=\"nofollow noopener\" target=\"_blank\">RedLine<\/a>, Acreed, and <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/25\/crooks-push-mac-malware-through-fake-openai-codex-ads\/5291899\" rel=\"nofollow noopener\" target=\"_blank\">Atomic Stealer<\/a> have all been fingered by Anthropic as being used to steal Claude credentials, sessions, and cookies.<\/p>\n<p>As for WorriedAssociate, they copped to making a noob mistake that led to their infection.\u00a0<\/p>\n<p>\u201cI got fooled like a rookie by downloading a cracked game,\u201d they admitted in a comment on their post. \u201cNever again.\u201d\u00a0<\/p>\n<p>As in their post, WorriedAssociate told us in a chat that they gave credit to Anthropic for cluing them in to the fact that they hadn\u2019t fully secured their accounts, and said they appreciated what the company did to help lock their Claude account down.\u00a0<\/p>\n<p>\u201cThere have been several cases on Reddit in the past of accounts being hacked to steal tokens, and Anthropic\u2019s customer service seems pretty dreadful when it comes to refunds and account recovery,\u201d they told us. \u201cThis email appears to be new, and measures have finally been put in place to protect AI users.\u201d<\/p>\n<p>\u201cTokens are valuable and can be resold,\u201d WorriedAssociate added. So let this be a lesson: Providers might not catch every case of account theft, and AI accounts are the new hotness. Don\u2019t let your tokens be burned by someone else &#8211; they\u2019re expensive and the last thing you want them to be used for is someone else&#8217;s work. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"security Commodity malware steals authenticated sessions, letting thieves freeload on victims&#8217; paid usage Rather than paying for their&hellip;\n","protected":false},"author":2,"featured_media":756332,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-756331","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/756331","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=756331"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/756331\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/756332"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=756331"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=756331"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=756331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}