A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
August 31, 2026
Anthropic proactively signed an unknown number of users out of Claude after a threat actor stole their login sessions, accessed their accounts, and consumed their allotted usage.
The attacks came to light via email alerts sent to affected users that were then posted to social media. The theft of login sessions and unauthorized access to Claude accounts resulted from infostealer malware on users' systems, rather than from any malware related to or installed through Claude, Anthropic said in the email notifications.
The AI company said it had signed affected users out of Claude and removed their saved payment methods after detecting suspicious activity on their accounts. Anthropic's ongoing investigation has found that the threat actor stole Claude login sessions using general-purpose infostealers that had previously been installed on users' systems, likely through a malicious app or unofficial download.






