Infostealers harvested Claude session cookies and replayed them past 2FA, and some hijacked accounts held standing access into corporate Gmail and Drive.

Anthropic warns Claude users that infostealer malware stole session cookies, letting hackers hijack accounts and drain paid usage quotas without

A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.