Anthropic Claude Users Locked Out After Infostealer Attack Hijacks Login Sessions

www.news4hackers.com-anthropic-claude-users-locked-out-after-infostealer-attack-hijacks-login-sessions-anthropic-claude-users-locked-out-after-infostealer-attack-hijacks-login-sessions

Anthropic initiated account lockouts for Claude users after detecting session compromises caused by infostealer malware.

Overview of the Incident

Anthropic initiated account lockouts for Claude users after detecting session compromises caused by infostealer malware. The malicious software involved in this incident includes Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows systems, alongside Atomic Stealer (AMOS) on a limited number of macOS devices. The company notified affected users via email last week, detailing the breach.

Malware Involved

The malicious software involved in this incident includes Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows systems, alongside Atomic Stealer (AMOS) on a limited number of macOS devices.

Response Measures

Session hijacking has emerged as a critical threat vector, bypassing traditional two-factor authentication mechanisms. Attackers exploit session cookies issued by platforms after successful logins, allowing them to maintain access without requiring credentials. This method enables adversaries to impersonate authenticated users without triggering 2FA prompts. In response to the breach, Anthropic implemented measures to mitigate damage. The company forcibly logged users out of their accounts to invalidate compromised sessions, removed stored payment information, and issued refunds for unauthorized transactions.

Remediation Process

Affected individuals have shared screenshots of account suspensions on public forums, outlining procedures to restore access and prevent further exploitation. The remediation process requires users to prioritize malware removal before addressing account recovery. Anthropic emphasized that signing out of Claude does not eliminate the underlying threat, urging victims to first conduct comprehensive system scans and eliminate any detected malicious software.

  • Resetting passwords and re-enabling two-factor authentication for the Claude account
  • Updating saved credentials in web browsers and reviewing financial statements for unauthorized activity
  • Re-adding payment methods if continued use of the service is intended

Users are also advised to terminate active sessions across other online platforms, log out, and re-authenticate to ensure all compromised sessions are invalidated.

Company Clarification

Anthropic clarified that the attack was linked to a threat actor targeting devices with malware, not related to the Claude platform itself. The company stated there is no evidence the malware was distributed through Claude or connected to user activities within the service. Mobile devices such as smartphones and tablets were not affected.

Security Recommendations

Individuals who identified malware infections traced to Claude users should remain vigilant against phishing attempts leveraging this incident as a social engineering tactic. Cybersecurity experts have noted an increase in impersonation campaigns exploiting high-profile breaches to deceive victims. The incident highlights the evolving tactics of cybercriminals, emphasizing the need for proactive endpoint security and regular system audits. Organizations are encouraged to reinforce user education on detecting and responding to session-based attacks.

Anthropic clarified that the attack was linked to a threat actor targeting devices with malware, not related to the Claude platform itself.


Blog Image

About Author

en_USEnglish