Anthropic warned that information-stealing malware is compromising active Claude sessions, allowing attackers to take over accounts and exhaust victims’ API-token and usage quotas. Reported infostealers include Vidar, Lumma, StealC, RedLine, and Atomic Stealer; the activity primarily affects Windows systems and a limited number of macOS devices, with no reported evidence involving mobile devices. One Claude Max subscriber observed usage increase from 45% to 55% despite having stopped scheduled tasks and not using the service.
Anthropic invalidated affected sessions, reset authorizations, logged out impacted users, removed stored payment details, and said it would refund apparent unauthorized excess-use charges. Users should remove suspicious or pirated software and perform a comprehensive malware scan before regaining access or restoring payment data. Detection may be difficult because Claude’s interface shows aggregate token consumption as a percentage rather than attributing usage to individual tasks; one affected user reportedly waited two weeks for account restoration.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Okta Threat Intelligence published research analyzing a 7 GB infostealer-data dump released on Telegram, identifying unexpired session tokens, JWTs/JWEs, and plaintext API keys affecting Anthropic and multiple other AI-service providers. The analysis described replay of stolen sessions and cited substantial AI-service fraud, including stolen credits and excess usage charges.
Anthropic notified some affected users, terminated suspicious sessions, reset authorization, and logged impacted users out. It removed stored payment details and provided refunds or proportional reimbursements for apparent unauthorized usage; De Swardt's account restoration took two weeks.
UK AI consultant Grant De Swardt observed his Claude Max usage rise from 45% to 55% despite stopping scheduled Cowork tasks and not using the chatbot. Anthropic determined that a compromised session key had enabled third-party access to his account, and other users subsequently reported similar unexplained consumption.
A malicious actor used infostealer malware, including Vidar, Lumma, StealC, RedLine, and Atomic Stealer, to steal Claude credentials and active browser sessions from affected computers. The stolen sessions were used to access accounts and consume victims' Claude token or usage quotas; Anthropic said the malware was not distributed through Claude.
OpenAI identified and banned ChatGPT accounts associated with the Russian-speaking ScopeCreep threat actor, which used the service to develop Windows malware and command-and-control infrastructure. OpenAI also coordinated with the code-hosting provider to remove a trojanized repository impersonating the Crosshair-X gaming overlay; the malware included credential and session theft capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceheise.de
Open sourceokta.com
Open sourcezdnet.fr
Open sourceopenai.com
Open sourceopenai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.