Claude Accounts Hacked: Anthropic Signs Out Users and Refunds Unauthorised Charges

August 31, 2026
Claude Accounts Hacked Anthropic Signs Out Users
68
Views

Claude accounts hacked is the latest cybersecurity concern affecting users of Anthropic’s AI platform. Infostealer malware on compromised computers has reportedly been used to steal active Claude login sessions, allowing attackers to access accounts and consume usage without permission.

Anthropic is responding by signing out affected users, removing saved payment methods and refunding charges it identifies as unauthorised. The incident highlights a growing security risk for AI users: attackers may not need to break into an AI platform directly if they can steal an authenticated session from an infected device.

How Claude Accounts Were Compromised

According to recent reporting, attackers used infostealer malware to obtain active Claude login sessions from infected computers.

Unlike traditional credential theft, infostealers can target browser data, authentication cookies and other information stored on a device. If an attacker obtains a valid session, they may be able to access an account without having to immediately defeat its password protection.

In the Claude incidents, stolen sessions were reportedly used to access accounts and consume users’ available Claude usage.

This makes the attack particularly concerning for paid Claude subscribers and users who maintain high usage limits.

Anthropic Is Signing Out Affected Users

Anthropic has begun taking action against accounts it believes may have been affected.

The company is signing out impacted users, removing saved payment methods and refunding charges that it determines were unauthorised.

The response is designed to limit continued unauthorised access and prevent attackers from continuing to consume account resources.

Users who believe they have been affected should also review their account activity and contact Anthropic support if they notice suspicious charges or activity.

Anthropic provides official guidance for requesting a Claude refund, including instructions for users who cannot access their account.

Which Malware Families Are Involved?

Anthropic has reportedly identified several infostealer malware families in connection with the activity, including:

  • Vidar
  • LummaC2
  • StealC
  • RedLine
  • Acreed

These types of malware are designed to steal information from infected computers. Depending on the malware and the environment, stolen information can include browser credentials, session data and other sensitive information.

The important point for Claude users is that the compromise can occur outside the Claude platform itself.

If malware is already present on a computer, an attacker may be able to steal an authenticated session before the user even realises the device has been compromised.

Why Changing Your Password May Not Be Enough

Users often respond to a suspected account compromise by changing their password.

That is an important step, but it may not always be sufficient when an attacker has stolen an active session.

A stolen session can potentially allow an attacker to access an account using existing authentication information.

For that reason, users should also:

  1. Sign out of affected sessions where possible.
  2. Change their Claude password.
  3. Review account and billing activity.
  4. Remove unfamiliar payment methods.
  5. Check the computer for malware.
  6. Update the operating system and browser.
  7. Review other accounts used on the affected device.
  8. Contact Anthropic support if suspicious activity continues.

Users should avoid simply changing the password and assuming the underlying problem has been resolved if the computer itself remains infected.

The Bigger Risk of Infostealer Malware

Infostealers are not specifically an AI threat.

They are a broader cybersecurity problem that has existed for years.

What makes the Claude incident particularly notable is how stolen authentication sessions can be monetised through AI services.

Attackers may use compromised accounts to consume paid AI resources, access sensitive conversations or potentially abuse the service for other activities.

As AI services become more valuable and usage limits become increasingly important, compromised accounts can become attractive targets.

Why AI Accounts Are Becoming High-Value Targets

AI accounts can contain more than simple chat histories.

Depending on how the service is used, an account could provide access to:

  • Private conversations
  • Business information
  • Uploaded documents
  • Coding projects
  • Research material
  • Connected tools
  • Paid usage allowances
  • API or development workflows

This makes AI account security increasingly important for both individuals and organisations.

Companies using Claude for professional work should treat AI accounts as part of their broader identity and access management strategy.

Claude Security Is Part of a Bigger AI Security Challenge

The incident arrives at a time when cybersecurity concerns around AI platforms are already increasing.

Anthropic has previously documented cases involving malicious use of Claude and has published research into how threat actors can use AI capabilities during cyber operations.

The company has also investigated incidents where Claude models interacting with third-party evaluation environments gained unauthorised access to real-world systems.

These incidents are different from the current infostealer situation, but they point to the same broader reality: AI security now involves both protecting AI systems and protecting the users who operate them.

What Claude Users Should Do Now

If you use Claude on a computer that may have been exposed to infostealer malware, take the situation seriously.

1. Check Your Claude Account

Look for unfamiliar activity, unexpected usage or charges that you do not recognise.

2. Secure the Device

Run a reputable malware scan and make sure your operating system, browser and security software are fully updated.

3. Change Your Password

Change your Claude password from a device you trust.

If you reused the same password elsewhere, change it on those services too.

4. Review Payment Information

Check your saved payment methods and recent transactions for anything unexpected.

5. Contact Anthropic

If you find suspicious activity, contact Anthropic through its official support channels.

Anthropic’s support documentation explains how users can request refunds and handle account access issues.

Businesses Need Stronger AI Account Security

The incident should also get the attention of organisations using AI tools across their workforce.

Employees increasingly use AI assistants for coding, research, documentation, analysis and other business processes.

That makes AI accounts another part of the company’s digital attack surface.

Businesses should consider implementing:

  • Strong authentication
  • Multi-factor authentication where available
  • Device security controls
  • Endpoint monitoring
  • Least-privilege access
  • Regular credential rotation
  • Employee security awareness training
  • Monitoring for unusual AI usage

Organisations should also establish clear policies for what confidential information employees can upload to external AI platforms.

AI Security Is Moving Beyond the Model

One of the biggest lessons from the incident is that securing an AI service is not enough.

An organisation can have strong security controls at the platform level and still have an account compromised because the user’s computer was infected.

This creates a wider security chain:

Device → Browser → Authentication Session → AI Account → Data and Usage

A weakness at any point can potentially affect the entire chain.

As AI becomes embedded in everyday business operations, organisations will need to protect this entire ecosystem rather than focusing exclusively on the model itself.

Final Thoughts

The Claude account compromise is a reminder that AI services are becoming valuable targets for cybercriminals.

The reported use of infostealer malware to hijack active Claude sessions shows that attackers do not necessarily need to break directly into an AI company’s infrastructure. Compromising the user’s device can be enough to gain access to an authenticated account.

Anthropic’s decision to sign out affected users, remove saved payment methods and refund identified unauthorised charges shows the seriousness of the situation.

For Claude users, the safest approach is straightforward: check your account, secure your device, change your password and investigate any unfamiliar activity.

The incident also highlights a larger trend in cybersecurity. As AI becomes more valuable, AI accounts, sessions and usage credits will increasingly become targets for attackers.

Protecting AI therefore means protecting not only the models and platforms, but also the devices, identities and people connected to them.

Article Categories:
Anthropic

Leave a Reply

Your email address will not be published. Required fields are marked *

The maximum upload file size: 3 GB. You can upload: image, audio, video, document, spreadsheet, interactive, text, archive, code, other. Links to YouTube, Facebook, Twitter and other services inserted in the comment text will be automatically embedded. Drop file here