Technology 18 sources · over 6 days Latest coverage 5 Sept 2026, 9:05 am UTC

Hackers Use Malware to Hijack Claude AI Accounts and Drain Subscriptions

A major cyberattack has compromised Claude AI user accounts through infostealer malware, prompting Anthropic to lock accounts, remove payment data, and warn users as attackers spread further malware.

By Luca Moretti · First published 5 Sept 2026

In brief

  1. Hackers used infostealer malware to steal active login sessions from Claude AI users, allowing them to hijack accounts.
  2. Anthropic responded by signing out affected users, deleting payment methods, and issuing refunds for unauthorized charges.
  3. The attackers bypassed two-factor authentication by abusing stolen session cookies, making traditional security measures ineffective.
  4. A fake Claude Opus 5 desktop app was discovered distributing additional malware aimed at stealing passwords and cryptocurrency wallets.
  5. Anthropic continues to investigate, warn users, and take steps to protect accounts while the threat remains active.
Hackers Use Malware to Hijack Claude AI Accounts and Drain Subscriptions
Source: Times of India Top Stories

Timeline · 8 moments

8 moments Open the full timeline →

Anthropic warns users of session hijacking via infostealer malware

Times of India Top Stories ↗

Company locks compromised accounts and removes payment methods

SecurityWeek ↗

Refunds issued for unauthorized usage and charges

AI (@ai) — Сообщество на vc.ru ↗

Fake Claude Opus 5 app discovered distributing RevStealer malware

GBHackers On Security ↗

Malware campaign exploits demand for AI tools to steal data and crypto

Cyber Security News ↗

Malicious GitHub repository spreads fake Claude app and wipes tracks

Help Net Security ↗

Researchers confirm fake Claude desktop app targeting passwords and wallets

r/Malware ↗

Incident highlights risks of session hijacking and limits of 2FA

DEV Community ↗

How it started

The trouble began when security researchers and users noticed suspicious activity in Claude AI accounts. Attackers had found a way to steal active login sessions using infostealer malware. This type of malware infects a user's device and grabs the session tokens used by browsers to keep users logged in, allowing hackers to access accounts without needing passwords or triggering two-factor authentication.

Anthropic, the company behind Claude, quickly identified the threat. They traced the problem to malware families like Vidar and RedLine on Windows, as well as Atomic Stealer on macOS. With these tools, cybercriminals could hijack accounts and make unauthorized purchases using stored payment methods.

How it unfolded

On August 31, Anthropic began warning users about the ongoing attacks and the risks of malware stealing active login sessions. They started signing out compromised accounts and removing payment methods to prevent further losses, as reported that day.

Affected users received notifications about the breach, and Anthropic initiated refunds for any unauthorized charges. Security experts confirmed that the malware could bypass standard security protocols, including two-factor authentication, because it used already-authenticated session tokens.

The situation escalated on September 1 when researchers discovered a fake desktop app called Claude Opus 5 circulating online. This app, which was not released by Anthropic, contained the RevStealer malware. Once installed, it could steal browser data, passwords, and even cryptocurrency wallet information from Windows users.

Further investigations revealed that the campaign behind the fake app was turning the popularity of Claude AI into a lure for more victims. The malware was distributed through a trojanized Electron application and a malicious GitHub repository. Security teams and Anthropic continued to alert users and take down fake sites.

Where it stands

Anthropic has locked out affected users, removed compromised payment information, and issued refunds for confirmed unauthorized transactions. The company is still investigating the full scope of the breach and encouraging users to check their devices for malware.

The attackers exploited a weakness in session management rather than a flaw in Claude itself, making device security the main concern. Anthropic and security experts are urging users to revoke active sessions, run malware scans, and be wary of third-party Claude apps or downloads.

What to watch

It remains unclear how many users were affected and whether the attackers will attempt new strategies. Anthropic is likely to introduce further security measures, and users are being advised to stay alert for further phishing attempts or malware campaigns targeting AI platforms.

Written from 18 outlets' coverage of this story. Every timeline entry links to the original report.

More in Technology

All →