Anthropic has notified some Claude users that third parties used login sessions stolen from infected devices to consume their usage allowances. BleepingComputer reported this on August 30, based on emails sent to affected users. According to the report, Anthropic signed out affected users, deleted saved payment methods, and refunded charges it determined to be fraudulent.
What the company flagged wasn't Claude-specific malware. Rather, the explanation points to infostealers—malware that broadly harvests passwords and browser data from a device—that also extracted already-authenticated Claude sessions. This kind of abuse could explain why usage might drop even when a user hasn't been active. However, Anthropic has not disclosed the number of affected users, the timeframe of the incident, or how it was detected.
The Target Was the "Post-Authentication" Session
When a login succeeds on a web service, the service issues a session that confirms the user has passed identity verification. Browsers store this as cookies or tokens, letting users open pages without re-entering passwords or multi-factor authentication each time. This convenience comes at a cost: the authenticated session itself becomes a high-value credential.
If a third party duplicates a valid session and replays it from an environment the service accepts, they may be able to act as the legitimate user without ever passing through the login screen. In a separate attack analysis published in April 2026, Microsoft reported cases where stolen authentication tokens were used without re-entering credentials or multi-factor authentication, with access continuing until the active session expired. Multi-factor authentication itself wasn't broken—rather, the proof that had already passed that check was reused.
Regarding this incident, BleepingComputer reported that Anthropic identified Vidar, LummaC2, and StealC on Windows, and Atomic Stealer (AMOS) on a small number of Macs. None of these are Claude-specific; they are general-purpose tools that collect everything from browser login cookies to credentials for other applications. Anthropic has also stated it has no reason to believe the malware was related to Claude or was distributed through Claude.
Exactly what was stolen remains unclear. Anthropic describes the incident as involving "Claude login sessions," but hasn't disclosed which files, token formats, or validity periods were affected. There has also been no announcement confirming that chat history or connected services were actually accessed, so it's not possible to treat the fraudulent usage consumption and any potential data exposure as a single, continuous incident.
Usage Limits and API Billing Aren't the Same Wallet
The unauthorized use appeared as "limit depletion" because Claude subscriptions share the same usage cap across multiple interfaces. According to Anthropic's help documentation, usage across claude.ai, Claude Code, and Claude Desktop all counts against the same limit. If a third party runs Claude using a stolen session, it depletes the legitimate user's remaining allowance too.
This needs to be understood separately from the Claude API's pay-as-you-go billing. Consumer subscriptions authenticate to Claude's web, app, and Claude Code interfaces through methods that include OAuth. Developers connecting products or external tools to the API, on the other hand, typically use API keys generated through the Console. The fact that sessions were stolen doesn't mean API keys were also compromised.
Anthropic's account management interface treats these separately. Web, mobile, and Desktop sessions can all be logged out together from Settings > Account, but Claude Code's authorization tokens must be deleted separately under Settings > Claude Code. If there's suspicious activity on a Console API key, that specific key needs to be revoked in the Console. Signing out from the browser alone doesn't invalidate every type of credential.
The length of web sessions also matters when assessing exposure time. Anthropic's current help documentation states that claude.ai sessions last 28 days, and that active use refreshes the session hourly, extending it 28 days from that point. Longer session lifespans mean fewer logins, but they also raise the stakes of explicitly terminating a stolen session.
Two Distribution Paths Impersonating Claude
The infection vector in this specific incident has not been disclosed. Still, throughout 2026, researchers observed repeated attacks that exploited trust in users searching for Claude to distribute malware.
In a case investigated by Huntress in July called MacSync, a user searching Google for how to install Claude Code was directed by an ad to a shared conversation hosted on the legitimate claude.ai domain. The page mimicked official installation instructions and asked the user to paste a command into Terminal. Running it triggered a six-stage attack chain that ultimately deployed information-stealing functionality.
In a separate investigation dubbed FakeAgent, malicious Claude Desktop installers were executed at at least 29 organizations between July 21–22. The entry point was again a malicious Artifact published on the legitimate claude.ai domain, which Huntress reported ultimately deployed SectopRAT.
Both investigations reveal a distribution method that can't be stopped simply by spotting fake domains. Attackers used advertising to elevate user-generated content on a legitimate domain, disguising it as official installation pages. Claude Code's official documentation and a shared conversation or Artifact published by anyone else may appear to be on the same domain, but they carry very different levels of trustworthiness.
However, there is no evidence linking these attacks to the session abuse Anthropic detected in this incident. Anthropic's email instead suggests the more general possibility that devices were infected through ordinary downloads or malicious apps, with Claude sessions being just one piece of a much larger haul of stolen information. The past distribution cases illustrate real-world entry points, but they don't identify the cause of this specific incident.
What to Stop Before Changing Your Password
When a session is stolen, decontaminating the device, invalidating the session, and updating credentials are three separate steps. The email Anthropic sent to affected users warned that signing out would stop the stolen session, but wouldn't remove the malware itself. If the user logs back in on the same infected device, any new session could be stolen just as easily.
| Where the Attack Persists | Immediate Action | Boundary of the Action |
|---|---|---|
| Suspected infected device | Disconnect from the network and investigate/decontaminate using organizational procedures or trusted security software | Logging out of Claude does not remove the malware |
| Claude Web, Mobile, Desktop | From a safe device, go to Settings > Account and log out of all devices | This invalidates existing sessions separately from changing your password |
| Claude Code | Delete unnecessary or suspicious authorization tokens under Settings > Claude Code | Managed separately from the full logout on the web side |
| Login source (email, Google, etc.) | End active sessions and review credentials and recovery settings | Infostealers collect data beyond just Claude |
| Console API Keys | Delete the key if there is suspicious API usage, and regenerate it in a secure environment | API key theft has not been confirmed across all affected users in this incident |
Reversing this order risks feeding new secrets back into a compromised device. First, isolate the device. Then, from a separate, safe device, terminate the sessions. After that, secure login sources including email and Google, and update any necessary credentials. Organizations need to follow their own incident response procedures for device rebuilding, scope investigation, and audit log preservation.
Claude's Account screen lets users review the device, browser, approximate location, and last update time for each session. Unfamiliar entries can be terminated individually, but a normal-looking session list doesn't guarantee the absence of infection. In cases like this one, where the company itself detects abnormal usage, or when usage doesn't match a user's own activity, session lists and usage history should be reviewed together.
Before the Scale of the Breach, Detection Criteria Need to Be Disclosed
Anthropic's response has gone as far as containing the damage after stolen sessions were used. Signing users out, deleting payment methods, and refunding fraudulent charges are concrete steps. At the same time, the company hasn't disclosed how many users were affected, when the abuse began, or what behavior it used to distinguish the legitimate user from the attacker.
Users also face a blind spot in what they can observe. Because multiple Claude products share the same usage limit, a sudden drop in remaining allowance alone can't distinguish between legitimate use on another device, a long-running Claude Code task, and abuse of a stolen session. Without being able to cross-reference access times, products, and usage per session, it's difficult to identify the cause in cases where the Account screen shows no unfamiliar devices.
For organizations, questions remain about how quickly notifications follow detection and how broadly sessions get revoked in bulk. Infostealers aren't malware built to target a single service and stop there—they harvest all the credentials stored in a browser at once. Once anomalies are found in Claude, the same response may need to extend to email, cloud services, and development environments.
The next piece of information to watch for is the timeframe and scope of the incident that Anthropic discloses. An explanation of the signals used to identify the anomaly, and how recurrence will be prevented, is also essential. If users gain the ability to audit consumption by product and by session, and to force suspicious sessions back into re-authentication, then a sudden drop in usage allowance could function as an early warning of a breach—rather than something discovered only after a billing dispute.
