Infostealer Malware Bypasses MFA to Hijack Claude Accounts
What happened
Anthropic disclosed, via reporting by BleepingComputer, that multiple infostealer malware families are actively harvesting authenticated browser session tokens from infected endpoints and using them to access Claude accounts. Because the attack operates on a valid, already-authenticated session, it bypasses password controls, multi-factor authentication, and single sign-on entirely. The named malware variants -- Vidar, LummaC2, StealC, RedLine, and Atomic Stealer -- are commodity tools widely available in criminal markets and already implicated in credential-theft campaigns across enterprise environments. Anthropic is proactively revoking sessions it identifies as compromised, removing stored payment methods, and offering refunds for fraudulent charges it can attribute, though the company has not disclosed how many accounts were affected or how it identifies compromised sessions. For enterprises, the exposure extends beyond billing fraud to the content of active sessions, which may include confidential data, internal documents, or sensitive prompts submitted through Claude.
Why it matters
- ·Standard AI platform access controls -- MFA, SSO, and password policies -- provide no protection against session token theft, which means organizations deploying Claude under the assumption that strong authentication is sufficient have a material gap in their AI API credential management posture.
- ·Enterprise teams running shared Claude accounts, team subscriptions, or browser-based access from endpoints that also handle email, file downloads, or browsing face the highest exposure, because infostealer malware typically enters via phishing or trojanized software on general-purpose workstations.
- ·Anthropic's remediation depends on its own detection capability, which means enterprises cannot independently verify whether their sessions were compromised or confirm the scope of any unauthorized access, creating an audit trail gap that matters for incident response and potential breach notification obligations.
Governance controls affected
What to do now
- ☐Audit all Claude accounts used by employees to identify browser-based sessions active on shared or general-purpose endpoints, and rotate or revoke those sessions immediately.
- ☐Review whether your Claude deployment relies on saved payment methods in shared team accounts, and remove stored billing credentials where not operationally required.
- ☐Evaluate whether your organization's Claude access model isolates API key-based access from browser session-based access, and restrict browser-based access to dedicated, hardened endpoints where feasible.
- ☐Establish a vendor incident notification workflow with Anthropic so that if the company identifies a compromised session tied to your organization's accounts, you receive timely notification rather than relying on self-discovery.
- ☐Update your AI incident response playbook to include session token compromise as a named threat scenario, with defined steps for evidence preservation, scope assessment, and breach notification evaluation.
What to watch next
Compliance teams should monitor whether Anthropic provides enterprise customers with structured disclosure of affected accounts, including timestamps and scope of unauthorized access, which would be necessary to support breach notification assessments under applicable privacy laws. The infostealer malware families named in this disclosure are the same categories of tools flagged in recent credential-theft campaigns against enterprise SaaS platforms, so teams should track whether similar session-hijacking incidents emerge across other AI vendors. As agentic AI deployments expand the number of non-human identities and API credentials attached to Claude and similar platforms, the attack surface for post-authentication session exploitation will grow, making endpoint isolation and credential segmentation increasingly important governance requirements.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
