TechDogs-"Anthropic Claude Subscribers Face Token Theft As Infostealers Hijack Login Sessions"

Cyber Security

Anthropic Claude Subscribers Face Token Theft As Infostealers Hijack Login Sessions

By Utkarsh Hiwale

Updated on Wed, Sep 9, 2026

Overall Rating

Hackers are hijacking Claude subscriber accounts using stolen login sessions, allowing them to consume paid AI usage without passwords or fresh authentication, as Anthropic warns affected users about infostealer malware targeting session credentials.


The incidents do not currently point to a breach of Anthropic’s infrastructure. Instead, attackers appear to be stealing authentication data from compromised user devices and replaying those sessions to access Claude accounts.


TL;DR

 
  • Claude subscribers have reported paid usage being consumed while they were inactive, with Anthropic linking some incidents to stolen login sessions.
  • Infostealer malware can capture session credentials and allow attackers to bypass normal password and multi-factor authentication checks.
  • Anthropic has invalidated sessions, removed saved payment methods and issued refunds in some cases, while users can review and terminate unfamiliar active sessions.


Claude Users Report Tokens Disappearing Without Using Their Accounts


According to TechCrunch, independent AI consultant Grant De Swardt first noticed unusual activity on his Claude Max 20x subscription on August 4, 2026, when his usage continued increasing despite him not working with Claude.


During one controlled period, De Swardt said his usage climbed from 45% to 55% even after he paused scheduled tasks, disabled cloud execution and had no active local Claude Code task.


Anthropic suspended his paid account while investigating, invalidated his sessions and server-side Claude Code tokens, and provided a £44.49 partial refund for the remaining period of his $200-per-month subscription.


TechCrunch reported that Anthropic later told De Swardt a compromised Claude session key had been used to create unauthorized Claude Code OAuth tokens. However, the company could not determine exactly how access to his session data had initially been obtained.

TechDogs ImageSource


Other Claude users subsequently reported similar unexplained usage on Reddit and GitHub, including accounts rapidly exhausting their available usage while the owners said they were not using the service.


Anthropic Links Some Account Hijacking To Infostealer Malware


Emails sent by Anthropic to some affected users said the company had "become aware of a bad actor" using common infostealer malware to steal Claude login sessions and consume account usage, according to TechCrunch.


Infostealers are designed to collect information such as saved credentials, browser cookies, authentication sessions and other sensitive information from infected computers. Once attackers obtain a valid session, they may not need to enter the victim's password again.


iTechPost noted that the reported incidents do not indicate that Anthropic's Claude infrastructure itself was breached. Instead, the evidence so far points toward compromised user devices and stolen authentication information.


Anthropic told affected users that it signed them out, invalidated existing authorizations and, in some cases, removed saved payment information and issued refunds. The company also said the malware was not delivered through Claude itself.


When TechCrunch asked Anthropic how users could identify unauthorized usage, however, the company declined to provide additional comment.


Stolen AI Sessions Can Bypass MFA


The problem is not limited to Claude.


The Hacker News reported on research from identity security company Okta showing how infostealer logs can contain reusable authentication secrets for numerous AI platforms.


Okta analyzed a 7 GB dataset released on Telegram on August 2, 2026, containing information from 5,871 infected machines across 162 countries. Researchers identified 561 Anthropic authentication tokens in the dataset, including 164 that remained unexpired when the dump was released.


The researchers also found 44,791 unique JSON Web Tokens across multiple services, of which 555 were considered likely related to AI-service authentication. Another 2,937 authentication-related encrypted JSON Web Tokens were identified.


Jeremy Kirk, Director of Okta Threat Intelligence, explained the risk clearly: "Once successfully replayed, a threat actor is effectively logged in to an LLM service without actually logging in."


That means stealing a valid session token can potentially bypass the password and MFA checks that normally appear during a fresh login.


The Hacker News also reported underground sellers advertising access to services including Claude, ChatGPT, Gemini and Cursor, reflecting a growing market for stolen AI accounts as premium model access becomes more valuable.


What Can Claude Subscribers Do?


Anthropic's official Claude Help Center allows users to review active sessions under Settings > Account. The page displays the device and browser associated with each session, an approximate location and information about when it was last active.


Users who discover a device or location they do not recognize can terminate that session remotely, forcing the device to authenticate again.

 



Security researchers also recommend treating AI authentication tokens and locally stored agent credentials with the same caution as passwords and other high-value secrets. Gen Digital separately reported that modern infostealers are increasingly adding Claude and other AI-assisted development tools to their collection lists.


Tempo, meanwhile, placed the Claude account incidents alongside broader questions surrounding Anthropic's approach to AI safety. However, the publication also noted an important distinction: compromised user sessions and wider concerns about advanced AI safety are separate security issues and should not be treated as evidence of the same failure.


For Claude subscribers, the immediate warning sign remains unexplained usage. Unexpected consumption while an account is inactive, unfamiliar active sessions or unauthorized account changes may warrant terminating sessions and checking the device itself for malware.

First published on Wed, Sep 9, 2026

Liked what you read? That’s only the tip of the tech iceberg!

Explore our vast collection of tech articles including introductory guides, product reviews, trends and more, stay up to date with the latest news, relish thought-provoking interviews and the hottest AI blogs, and tickle your funny bone with hilarious tech memes!

Plus, get access to branded insights from industry-leading global brands through informative white papers, engaging case studies, in-depth reports, enlightening videos and exciting events and webinars.

Dive into TechDogs' treasure trove today and Know Your World of technology like never before!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light