Infostealer malware is hijacking Claude sessions to drain your usage
Stolen session cookies replay past your 2FA. Anthropic is signing users out and refunding fraud — but can't kill the malware. Plus: EU's first AI Act probes.

Copy markdown
How it slips past your password and 2FA
Infostealers copy your already-authenticated Claude session cookie, not your password — so replaying it needs no login and sails straight past 2FA and SSO. Attackers then burn your usage limits and run up charges on your account.
Six malware families, on Windows and Mac
Anthropic flagged Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer (AMOS) hitting a smaller set of Mac users. If you got a sign-out email from Anthropic, assume one of these is on your machine.
What Anthropic already did to your account
The company signed affected users out, removed saved payment methods, and is refunding charges it flags as fraudulent. Its warning is blunt: signing you out kills the stolen session but does not remove the malware from your device.
Do this before you log back in
Run a full malware scan first, then reset your email password with 2FA on, revoke your other active sessions, and refresh browser-saved credentials. Treat AI-suggested links and paste-in terminal commands like unsolicited email attachments.
Elsewhere: EU opens its first AI Act probes
The EU AI Office has begun formally querying OpenAI, Anthropic and Google under now-live enforcement powers, over model security, external evaluations and training-data summaries. Weak answers risk fines up to €15M or 3% of global revenue — and the Commission can pull a model from the EU market.