Anthropic warns that some Claude users are being affected by infostealer malware that hijacks active Claude login sessions. In these cases, malware that is present on a user’s PC can reuse the user’s already-authenticated session, letting an attacker access the account and generate activity that consumes the user’s allotted usage.

Anthropic says it is not the result of Claude itself and that the malicious software spreads through downloads outside the service. According to the company, it has taken steps to protect impacted users, including logging them out. It also states that it is working to refund any unauthorized charges that result from the hijacked sessions. The reports emphasize that because the attacker uses a stolen session, common protections such as passwords and two-factor authentication may not stop the intrusion.

Across outlets, the core details are consistent: Anthropic issues a security alert, points to third-party infostealer malware on endpoints, and takes account-safety measures such as forced logouts and refunds for unauthorized usage.