CybersecuritySeptember 1, 2026· via Dark Reading

Infostealers Steal Session Data from Anthropic Users

Infostealers Steal Session Data from Anthropic Users

Image : Dark Reading

Researchers have uncovered a campaign in which infostealers were used to harvest session tokens and compromise accounts on Anthropic’s Claude AI platform. The attacks targeted an unspecified number of users, allowing the threat actor to take over active sessions without needing login credentials.

How the campaign unfolded

Threat actors deployed multiple infostealer families—malware designed to extract stored credentials, browser data, and session cookies from infected devices. Once inside a system, the malware collected active session tokens for Claude, giving the attackers persistent access to user accounts. Because session tokens often remain valid even after a user logs out or restarts a browser, the compromise could persist undetected for extended periods.

What users should do now

Anthropic has not disclosed the full scope of affected users, but security teams recommend immediate action. Users should revoke any active sessions in their Claude account settings, rotate passwords, and enable multi-factor authentication if not already active. Scanning devices with updated antivirus tools may also help identify residual infostealer infections. Anthropic has not indicated whether additional platform-level mitigations were implemented.

Why it matters

Infostealer-driven session theft highlights a growing risk for AI platforms that rely on web sessions for seamless user experiences. Unlike traditional credential theft, session hijacking bypasses authentication controls and can remain unnoticed for long periods. This incident underscores the need for AI providers to harden session management and for users to treat session tokens with the same care as passwords. Without stronger safeguards, similar attacks could erode trust in AI services and expose sensitive data at scale.


Source: Dark Reading. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Dark Reading →

← Back to home