Executive Summary
In August 2026, Anthropic detected unauthorized access to Claude AI accounts after threat actors used multiple infostealer malware variants including Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer to harvest user session cookies and authentication tokens. The attackers bypassed multifactor authentication by stealing active browser sessions rather than credentials, allowing them to consume users' Claude usage quotas and access saved payment information. Anthropic responded by forcibly signing out affected users, removing payment methods, and refunding unauthorized charges.
This incident exemplifies the growing shift from credential-based attacks to session hijacking, as organizations strengthen password policies and MFA adoption. The attack highlights emerging threats against AI platforms and the need for enhanced session management controls in cloud-native applications.
Why This Matters Now
Session hijacking attacks are surging as traditional credential theft becomes harder due to improved authentication. AI platforms are increasingly targeted for computational resources and sensitive data, making session security critical for protecting against unauthorized AI usage and data exposure.
Attack Path Analysis
Threat actors deployed multiple infostealers (Vidar, Lumma, StealC, RedLine, Acreed, Atomic Stealer) on user systems through malicious apps or unofficial downloads to harvest Claude session cookies and authentication tokens. The stolen sessions enabled direct account access bypassing MFA, allowing unauthorized consumption of Claude usage credits and potential data exfiltration from user conversations and prompts.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Users downloaded and executed malicious applications or unofficial software containing infostealers (Vidar, Lumma, StealC, RedLine, Acreed on Windows, Atomic Stealer on macOS)
MITRE ATT&CK® Techniques
Steal Web Session Cookie
Process Injection
Credentials from Web Browsers
Browser Session Hijacking
Spearphishing Attachment
Malicious File
Disable or Modify Tools
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication Controls
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
CISA ZTMM 2.0 – Session Management
Control ID: Identity-3
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Secure Log-on Procedures
Control ID: A.9.4.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI/ML platforms face session hijacking via infostealers targeting authentication tokens, bypassing MFA protections and enabling unauthorized access to development resources.
Financial Services
Infostealer malware compromises saved banking credentials and payment methods, requiring enhanced egress filtering and anomaly detection for financial data protection.
Professional Training
Educational AI tool compromises expose training data and user sessions, necessitating zero trust segmentation and encrypted traffic monitoring for learner protection.
Research Industry
Research organizations using AI platforms risk intellectual property theft through session token compromise, requiring multicloud visibility and threat detection capabilities.
Sources
- Anthropic Users Hit by Infostealer Attacks, Session Theftshttps://www.darkreading.com/cyberattacks-data-breaches/anthropic-users-infostealer-attacks-session-theftsVerified
- CISA Advisory on Infostealer Malware Threatshttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
- MITRE ATT&CK Framework - Credentials from Web Browsershttps://attack.mitre.org/techniques/T1555/003/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have likely reduced the blast radius of this infostealer campaign by constraining lateral movement and egress paths once attackers gained initial foothold. Segmentation controls could have limited the scope of credential harvesting and restricted unauthorized access to cloud services.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise of user endpoints would likely still occur, but CNSF visibility could have provided earlier detection of malicious network behaviors and constrained subsequent attacker movements within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: While credential harvesting on endpoints would likely proceed, Zero Trust segmentation could have limited the scope of stolen session tokens by restricting network access paths and reducing the attack surface for subsequent account compromise.
Control: East-West Traffic Security
Mitigation: Lateral credential harvesting across browser profiles would likely continue, but East-West traffic controls could have significantly constrained the attacker's ability to pivot between different cloud services and applications using stolen tokens.
Control: Multicloud Visibility & Control
Mitigation: Data exfiltration to external infrastructure could have been detected and potentially constrained through multicloud visibility, limiting the attacker's ability to process and weaponize stolen credentials at scale across different cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized Claude account access would likely still occur initially, but egress security controls could have limited the scope of data exfiltration and constrained the attacker's ability to extract large volumes of conversation history and sensitive prompts.
While some financial impact and data exposure would likely remain, the overall blast radius would be significantly reduced with constrained lateral movement, limited egress paths, and enhanced visibility enabling faster incident detection and response.
Impact at a Glance
Affected Business Functions
- AI Model Services
- Customer Account Management
- Payment Processing
- User Authentication Services
Estimated downtime: 1 days
Estimated loss: $50,000
Session tokens, authentication cookies, saved browser credentials, and payment information for an unknown number of Anthropic Claude users. Unauthorized usage of Claude API services and potential access to user conversation history.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to detect and block infostealer command and control communications to unauthorized destinations
- • Deploy threat detection and anomaly response capabilities to identify suspicious session usage patterns and unauthorized account access behaviors
- • Enable multicloud visibility and control to monitor for anomalous AI service interactions and repeated malformed requests indicating compromised sessions
- • Establish zero trust segmentation with identity-based policies to limit the scope of session token abuse and enforce least privilege access to cloud services
- • Deploy cloud firewall capabilities with URL filtering to prevent initial compromise through malicious downloads and block known infostealer infrastructure



