SECURITY Signal 20
Anthropic signs out Claude users and clears payment data to stop infostealer malware campaign
Anthropic forced a sign-out of affected Claude accounts and removed stored payment details after detecting malware that hijacks sessions to drain usage credits.
Engineers building on or integrating Claude must be aware that AI platform credentials are now a target for traditional infostealer malware, meaning compromised devices can lead to unexpected usage charges. The forced logout and payment wipe protect users financially but require them to clean infected machines and re-authenticate, adding operational overhead. The incident also highlights the need for stronger credential protection and device hygiene when accessing cloud AI services.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Anthropic identified an infostealer campaign on Windows and Mac PCs that steals Claude login sessions to consume usage credits.
Affected users were automatically signed out and their payment information was removed, with refunds offered for any unauthorized usage.
Users must run thorough malware scans, remove suspicious software, and re-enter payment details to resume normal service.
THE CLUSTER
↗