Anthropic Forces Claude Users Offline After Infostealer Attack

Modelli/fornitori correlati: Claude Anthropic Anthropic Fornitore
Anthropic Forces Claude Users Offline After Infostealer Attack
Article image

Anthropic has reportedly responded to a large-scale Claude account security incident by forcibly logging out affected users and removing stored Visa and Mastercard payment methods.

Article image

Users said they received no ban warning before being signed out. Anthropic described the measures as protection against attackers exploiting stolen AI usage rather than a routine account crackdown.

Article image

Infostealers targeted Claude sessions

Article image

In warning emails, Anthropic reportedly said that suspicious accounts had been logged out and their payment details deleted.

Article image

The named Windows malware families were Vidar, Lumma (LummaC2), StealC, RedLine and Acreed. Vidar steals browser credentials, history and cryptocurrency-wallet keys. LummaC2 has been widely reported, while StealC became a prominent malware-as-a-service family after Lumma activity declined. RedLine’s infrastructure was dismantled by Dutch police and the FBI in October 2024, and Acreed reportedly uploaded more than 4,000 logs during its first week of observation.

For macOS, Anthropic identified Atomic Stealer (AMOS), which can enter through cracked software or fake updates and target Keychain data and browser cookies. Stolen credentials may expose banking accounts, web versions of WeChat and Alipay, and corporate systems.

The incident gained attention after a Reddit user described having social accounts hijacked and used for cryptocurrency scams. After changing passwords and cleaning the malware, he received a Claude warning that an attacker was using the API to steal his token. Other users then reported unexpected logouts, forced reauthentication and missing cards.

Article image
Article image

Anthropic’s reported response was to disable infected accounts and delete saved card information to limit potential financial losses.

Article image

Why changing a password was not enough

Anthropic said attackers used infostealers to extract Claude login sessions from users’ computers. Those sessions could then be used to access accounts and consume their available usage.

Article image

A possible warning sign was usage resetting unexpectedly and then being exhausted while the account owner was inactive.

Article image
Article image

Passwords and two-factor authentication may not stop an attacker who already possesses a valid session cookie. The stolen cookie acts like an authenticated pass, allowing access without repeating password or 2FA checks.

Article image
Article image

Vidar, LummaC2, StealC, RedLine, Acreed and AMOS can target browser-stored cookies and session IDs. Attackers may reproduce the session environment and continue using the account. Revoking active sessions is therefore necessary; changing the password alone may leave existing sessions active.

Article image
Article image

Cracked software was linked to one infection

A Reddit victim said he had installed a cracked game downloaded from a Russian game-cracking forum. Commenters advised using unknown software only in an offline virtual machine, while others recommended avoiding unofficial downloads altogether.

Article image

The victim also asked Claude Opus 5 Max to inspect the computer. According to his account, it identified and disabled malware and linked the attack chain to activity documented by Malwarebytes in July 2026: RenPy Loader, PavinLoader and Amatera Stealer. Other commenters warned that an LLM should not replace a clean system reinstall, especially where a rootkit may be involved.

Article image

Stolen AI usage became a resale product

The reported motive was not necessarily direct payment-card theft. Attackers could combine stolen Claude sessions into unauthorized shared-access websites or generate API keys and resell access through API relay services. This turns stolen usage into a low-cost source of AI capacity, while unexpected API activity could also create substantial charges.

Article image
Article image
Article image

Recommended checks and response

Users were advised to look for unexplained usage exhaustion, unfamiliar conversation history, unexpected login prompts and missing payment cards.

Article image
  1. Sign out of all devices and revoke active sessions for core accounts such as Google, Claude and OpenAI.
  2. Clear all browser cookies and other site data.
  3. Avoid cracked, modified or unofficial software and games.
  4. If a high-risk infection is suspected, back up essential files and reinstall the operating system rather than relying solely on antivirus software or an AI assistant.
Article image
Article image

Condividi questo articolo