Anthropic forces Claude logouts after session-stealing attacks

Anthropic is forcibly logging some users out of Claude and removing saved payment methods after malware was found hijacking active sessions, BleepingComputer reports.
The company has terminated active sessions for affected accounts, removed stored payment methods and refunded unauthorized charges.
The attacks rely on infostealer malware that can extract active browser sessions from infected devices. That allows attackers to bypass passwords and two-factor authentication and quietly burn through a victim’s Claude usage limits.
Anthropic says the compromised devices were not infected through Claude itself. Infostealers typically reach computers through pirated software, malicious downloads or other untrusted applications.
Researchers have identified several malware families capable of stealing this kind of data. On Windows, they include Vidar, LummaC2, StealC, RedLine and Acreed, while Mac users can be targeted by Atomic Stealer.
Logging out invalidates the stolen session, but it does not remove the malware from the device. Anthropic recommends cleaning the infected computer first and changing passwords only after the malware has been removed.