Incident2026-08-30

Anthropic is warning Claude users that malware on their computers stole active login sessions. Attackers used those stolen sessions to enter accounts and burn through usage limits. Anthropic is signing affected users out, deleting saved payment methods and refunding charges it judges unauthorised. It says usage that refilled and then drained while the user was away is the likely sign. The malware is ordinary credential-stealing software, not linked to Claude or installed through it. It usually arrives via downloads or malicious apps and copies browser passwords, cookies and other credentials. A copied session can bypass the normal password and two-factor login. Anthropic named Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a few Macs. It warns that signing out does not remove the malware, so a new session could be stolen. Users are urged to change credentials, revoke other sessions and clean their machines.

What changed

Stolen Claude sessions were letting attackers use accounts undetected.

What it unlocks

Recognising drained usage limits as a sign of a hijacked login session.

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.