Hackers are hijacking the accounts of some paying users of Anthropic’s Claude artificial intelligence service, using stolen login sessions to consume subscribers’ usage allowances without their knowledge.

The attacks involve infostealer malware that can capture active browser sessions from infected computers. The stolen sessions can then be replayed by attackers, potentially allowing them to enter accounts without going through a conventional login or two-factor authentication process.

Anthropic has told affected customers that criminals have used compromised sessions to access Claude accounts and consume their usage.

One Claude Max subscriber, British AI consultant Grant De Swardt, noticed his usage rising even when he was not working. Anthropic later invalidated his sessions and Claude Code tokens and issued a partial refund after identifying suspicious third-party activity.

Anthropic has responded to some affected accounts by signing users out, removing saved payment methods and refunding charges deemed unauthorised. The company has said there is no indication that the malware itself originated from Claude.

The incidents highlight an emerging security risk around paid AI services: stolen authenticated sessions can be valuable because they provide access to expensive computing allowances as well as potentially sensitive account information.



Contact
reader@banginews.com

Bangi News app আপনাকে দিবে এক অভাবনীয় অভিজ্ঞতা যা আপনি কাগজের সংবাদপত্রে পাবেন না। আপনি শুধু খবর পড়বেন তাই নয়, আপনি পঞ্চ ইন্দ্রিয় দিয়ে উপভোগও করবেন। বিশ্বাস না হলে আজই ডাউনলোড করুন। এটি সম্পূর্ণ ফ্রি।

Follow @banginews