CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Anthropic cracks down on hijacked user accounts mining AI tokens

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5880

As cited

Copy frozen at (site build).

threat intel

Anthropic cracks down on hijacked user accounts mining AI tokens

Anthropic has detected and mitigated account hijacking attempts where threat actors used infostealer malware to steal Claude login credentials, sessions, and cookies for unauthorized premium service usage. The company identified malware families including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer targeting Claude sessions collected during broader credential theft campaigns. Anthropic proactively logged affected users out, removed payment methods, and notified users of compromise attempts.

Why it matters: Claude users and any organization relying on Claude services should assess whether their accounts have been compromised by common infostealer malware, change passwords, and review payment methods, as stolen sessions enable attackers to consume premium compute resources at the victim's expense.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Anthropic cracks down on hijacked user accounts mining AI tokens

Anthropic has detected and mitigated account hijacking attempts where threat actors used infostealer malware to steal Claude login credentials, sessions, and cookies for unauthorized premium service usage. The company identified malware families including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer targeting Claude sessions collected during broader credential theft campaigns. Anthropic proactively logged affected users out, removed payment methods, and notified users of compromise attempts.

Why it matters: Claude users and any organization relying on Claude services should assess whether their accounts have been compromised by common infostealer malware, change passwords, and review payment methods, as stolen sessions enable attackers to consume premium compute resources at the victim's expense.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary