Anthropic, the company behind the AI chatbot Claude, has warned some users that malware had stolen their session cookies, allowing unauthorized access to their accounts without needing to log in or bypass two-factor authentication. According to VentureBeat, the company identified several types of malware active on Windows systems, including Vidar, LummaC2, StealC, RedLine, and Acreed, as well as Atomic Stealer on a small number of Macs. These malicious programs are designed to extract session cookies and saved passwords from browsers, which are digital tokens that prove a user is already authenticated to a service. A session cookie is a piece of data stored by a browser that confirms a user has already logged in. While two-factor authentication (2FA) is used to secure the login process, once a user is authenticated, the service provides a cookie to the browser. If an attacker steals and replays this cookie from another device, the server treats the request as coming from the legitimate user, allowing access without needing a password or a verification code. Anthropic detected unusual activity through its usage tracking system, noting that some account quotas were being emptied without the account holders’ knowledge. The company responded by logging out affected users, removing payment methods, and refunding fraudulent charges, though it did not disclose the total number of affected accounts. The potential risks of such a breach extend beyond just financial loss. A compromised Claude session could grant access to all the data and tools a legitimate user has access to, including conversation history, uploaded files, and connected third-party services. Claude allows users to link their accounts to external services like Gmail, calendars, and file storage from Google Workspace, granting access to these services based on the user’s permissions. Read access to these services can occur without additional verification, while write actions—such as sending emails or deleting files—require explicit authorization. This means a hijacked session could potentially access sensitive information, like an employee’s personal or professional email, if their account was linked to it. VentureBeat notes that Anthropic has not confirmed whether the hijacked sessions actually accessed such data. The challenge lies in the fact that most of these accounts are personal subscriptions, paid for with credit cards and authenticated directly with Anthropic, rather than through enterprise identity systems. This makes it difficult for IT administrators to monitor or remotely log out these accounts. According to a report by LayerX cited in an Akamai study, nearly half of professional AI-related interactions occur through personal accounts, with 61% of such interactions using Claude specifically. Additionally, logging out of Claude does not automatically revoke access to third-party services like Google or Microsoft, which must be manually checked and revoked separately. This incident is part of a broader trend in cybersecurity. It follows a previous attack in July, documented by the cybersecurity firm Huntress, in which attackers created a fake download page for Claude on the claude.ai domain. This was done through a sponsored Bing ad that redirected users to a malicious site, compromising employees from at least 29 organizations within two days before Anthropic removed the affected content. Anthropic has stated that the malware is not linked to its platform and that the infected devices are the responsibility of the users. While this holds true for personal computers, it becomes more complex in professional environments, where companies are expected to manage and detect malware on their own systems.