Claude account hacked? If your Claude usage limit has been draining faster than expected, or you got signed out with no explanation, you are not alone. Anthropic has confirmed that a wave of Claude accounts were hijacked this week, not through a data breach on its own systems, but through malware sitting quietly on users’ own computers.
This is quickly becoming one of the most talked-about AI security stories of 2026, and it points to a risk that goes far beyond Claude itself.
How the Claude Account Hacked Incident Happened
Anthropic began emailing affected users on August 30, warning that infostealer malware on their devices had copied active Claude login sessions. Attackers then used those stolen sessions to log into accounts and burn through paid usage, all without ever needing a password or two-factor authentication.
The malware families involved include Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a small number of Mac devices. These are common, widely available infostealer tools, not something built specifically to target Claude.
Anthropic was clear that the malware did not come from Claude and was not installed through the platform. Most infections traced back to pirated software and unofficial downloads, the same entry points that have fueled credential theft for years.
Why Session Theft Is More Dangerous Than Password Theft
Two-factor authentication protects your login, but once you are signed in, your browser holds onto a session cookie so you do not have to log in again on every click. Infostealer malware copies that cookie directly. An attacker who reuses it is treated as an already logged-in, fully verified user, with no password and no 2FA prompt required.
That is what makes this kind of attack so effective against AI accounts specifically. Many people stay logged into Claude, ChatGPT, or similar tools across long sessions on the same device, which gives stolen cookies a longer shelf life for attackers to exploit.
How Anthropic Responded
In response to the campaign, Anthropic took three concrete steps for affected accounts:
- Signed out compromised sessions to cut off attacker access
- Removed saved payment methods so the account could not be charged again
- Refunded any usage charges it identified as unauthorized
The company also warned it may sign users out again if it detects further signs of misuse, and it is urging affected users not to re-add a payment method until they are certain the malware has been fully removed from their device.
What This Means If You Use Claude or Any AI Platform
Signing a user out only stops the stolen session. It does nothing to remove the malware still sitting on the device, which means the same attacker can steal a fresh session the next time that person logs back in.
If you use Claude, ChatGPT, or any subscription-based AI tool, here is what actually matters right now:
Run a full malware scan before logging back into any AI account, especially if you have downloaded pirated software, cracked games, or unofficial apps recently.
Change your password and enable two-factor authentication; even though 2FA alone would not have stopped this specific attack, it still closes off other entry points.
Check your usage history for spikes you do not recognize. A quietly draining usage limit is often the first visible sign something is wrong.
Be cautious of copycat emails impersonating Anthropic or other AI providers that try to use this incident as a pretext for phishing.
The Bigger Picture for AI Security in 2026
This incident is a reminder that AI platforms do not need to be breached directly for accounts to be compromised. As more people rely on AI tools daily, often staying logged in across multiple devices, session hijacking through infostealer malware is becoming one of the more practical threats in AI account security, not a theoretical one.
The fix is not really about Claude. It is about basic device hygiene: avoiding pirated downloads, keeping systems updated, and treating any sudden change in AI usage or billing as a signal worth investigating immediately.
For the full technical breakdown, see BleepingComputer’s coverage of the incident. For more on how session theft bypasses two-factor authentication, Help Net Security’s analysis breaks down the mechanics in detail.
Frequently Asked Questions
No. Anthropic has confirmed the malware did not come from Claude and was not installed through the platform. The infections happened on users’ own devices, typically through pirated software or unofficial downloads, and the malware then stole active Claude login sessions from the browser.
Check your Claude usage history for spikes you don’t recognize, or watch for unexpected sign outs. If Anthropic identified your account as affected, they would have emailed you directly. A quietly draining usage limit is often the first visible sign something is wrong.
Not on its own. Since attackers stole an active session cookie rather than your password, they bypassed the login step entirely. Changing your password helps going forward, but you also need to run a full malware scan and remove the infostealer from your device, otherwise it can steal your next session too.
2FA alone would not have stopped this specific attack, since the malware stole an already authenticated session rather than logging in fresh. That said, 2FA still closes off other common attack paths, so it’s worth keeping enabled alongside good device hygiene.
Run a full malware scan before logging back into any AI account, change your password with two factor authentication enabled, check your usage and billing history for anything unusual, and avoid pirated software or unofficial app downloads, which are the most common entry point for infostealers.
Have you noticed unusual activity on your AI accounts? Share your experience in the comments, and follow AI Web Reporter for ongoing coverage of AI security, tools, and industry developments.

