Executive Summary

In August 2026, Anthropic detected unauthorized access to Claude AI accounts after threat actors used multiple infostealer malware variants including Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer to harvest user session cookies and authentication tokens. The attackers bypassed multifactor authentication by stealing active browser sessions rather than credentials, allowing them to consume users' Claude usage quotas and access saved payment information. Anthropic responded by forcibly signing out affected users, removing payment methods, and refunding unauthorized charges.

This incident exemplifies the growing shift from credential-based attacks to session hijacking, as organizations strengthen password policies and MFA adoption. The attack highlights emerging threats against AI platforms and the need for enhanced session management controls in cloud-native applications.

Why This Matters Now

Session hijacking attacks are surging as traditional credential theft becomes harder due to improved authentication. AI platforms are increasingly targeted for computational resources and sensitive data, making session security critical for protecting against unauthorized AI usage and data exposure.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used infostealer malware to harvest active browser session cookies and authentication tokens, allowing them to hijack already-authenticated sessions without needing to defeat MFA controls.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have likely reduced the blast radius of this infostealer campaign by constraining lateral movement and egress paths once attackers gained initial foothold. Segmentation controls could have limited the scope of credential harvesting and restricted unauthorized access to cloud services.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise of user endpoints would likely still occur, but CNSF visibility could have provided earlier detection of malicious network behaviors and constrained subsequent attacker movements within the cloud environment.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: While credential harvesting on endpoints would likely proceed, Zero Trust segmentation could have limited the scope of stolen session tokens by restricting network access paths and reducing the attack surface for subsequent account compromise.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral credential harvesting across browser profiles would likely continue, but East-West traffic controls could have significantly constrained the attacker's ability to pivot between different cloud services and applications using stolen tokens.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Data exfiltration to external infrastructure could have been detected and potentially constrained through multicloud visibility, limiting the attacker's ability to process and weaponize stolen credentials at scale across different cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorized Claude account access would likely still occur initially, but egress security controls could have limited the scope of data exfiltration and constrained the attacker's ability to extract large volumes of conversation history and sensitive prompts.

Impact (Mitigations)

While some financial impact and data exposure would likely remain, the overall blast radius would be significantly reduced with constrained lateral movement, limited egress paths, and enhanced visibility enabling faster incident detection and response.

Impact at a Glance

Affected Business Functions

  • AI Model Services
  • Customer Account Management
  • Payment Processing
  • User Authentication Services
Operational Disruption

Estimated downtime: 1 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Session tokens, authentication cookies, saved browser credentials, and payment information for an unknown number of Anthropic Claude users. Unauthorized usage of Claude API services and potential access to user conversation history.

Recommended Actions

  • Implement egress security and policy enforcement to detect and block infostealer command and control communications to unauthorized destinations
  • Deploy threat detection and anomaly response capabilities to identify suspicious session usage patterns and unauthorized account access behaviors
  • Enable multicloud visibility and control to monitor for anomalous AI service interactions and repeated malformed requests indicating compromised sessions
  • Establish zero trust segmentation with identity-based policies to limit the scope of session token abuse and enforce least privilege access to cloud services
  • Deploy cloud firewall capabilities with URL filtering to prevent initial compromise through malicious downloads and block known infostealer infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image