Infostealer malware provided attackers access to live login sessions. If your usage limits reset and then drained while you were away from the keyboard, that’s a red flag.


by Tim Leogrande, BSIT, MSCP, Ed.S.

🗓  SEP 17 2026 • 2 MIN READ

📰  NEWS


According to an email Anthropic sent to impacted customers on August 30, some Claude users had infostealer malware on their systems that let attackers hijack login sessions and burn through usage limits. The company hasn't disclosed how many accounts were compromised, how long the campaign ran, or whether all reported cases share the same malware source.

An infostealer silently gathers private information from a computer or mobile device and sends it to a criminal third party. This attack vector isn't exclusive to Claude. Because the malware pulled passwords, session data, and other account details from browsers and other applications, it most likely reached user devices through malicious or unauthorized downloads.

Anthropic identified the Vidar, LummaC2, StealC, RedLine, and Acreed infostealers on Windows machines, as well as Atomic Stealer on a small number of Macs. The company reports that a threat actor was able to pick out Claude sessions from the stolen credential data.

<aside> 💡

Nothing was breached on Anthropic's end. The compromise happened on customers' own computers, which is why signing out the hijacked sessions treats the symptom but not the cause.

</aside>

Session theft is the most likely culprit if your usage limits reset and then drained again while you weren't using Claude. Anthropic responded to the campaign by signing out the impacted sessions, and said it would do so again if it detected more evidence of account misuse.

To protect accounts from additional charges, Anthropic removed saved payment methods and reimbursed users for any charges it determined were unauthorized.

Victims have been advised to make sure their systems are malware-free. They can then change their Claude login credentials and add a new payment method**.**


© 2026 Tim Leogrande. The opinions expressed herein are solely those of the author and don’t necessarily reflect the views, policies, or positions of any affiliated organizations or individuals.