
Anthropic signs out Claude users whose sessions were stolen by infostealer malware
Anthropic signed out Claude users whose session cookies were captured by six commodity infostealer families — Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer — and removed saved payment methods from the affected accounts. Stolen cookies bypass multifactor authentication outright, and paid LLM accounts are now a routine target for ordinary malware crews: one notified victim was compromised after downloading a cracked game.
Source: theregister.com ↗