AI news

Claude account security alert: infostealer malware is draining usage quotas

Anthropic has warned Claude users about infostealer malware that hijacks login sessions to drain AI usage quotas. Here is what happened and what to do.

Anthropic, the company behind the Claude assistant, has warned some users about information-stealing malware (an “infostealer”) that hijacks their login sessions. The attackers’ goal is not to read your chats but to take over accounts and burn through their AI usage quota, which can lead to extra charges.

What happened

According to an alert email shared by a Reddit user, a threat actor is “using a common infostealer to steal Claude login sessions from users’ computers, then using those sessions to access Claude accounts and exhaust their usage limits.” A tell-tale sign, Anthropic notes, is usage limits that appear to refill and then drain while you are not using Claude.

Which malware, and which devices

The campaign relies on well-known infostealer families: Vidar, Lumma, StealC and RedLine on Windows, plus Atomic Stealer on a “small number of Macs.” There is currently no evidence that phones or tablets are affected. These tools quietly harvest saved credentials, browser data, financial details and crypto wallets, and AI-platform sessions are now on that target list too.

What Anthropic did

Anthropic logged out affected users and deleted their stored payment information as a precaution, and says it is refunding usage charges that appear to be unauthorized. The company stresses it has “no reason to believe this malware is related to Claude” or was installed through it, the infection comes from the user’s own device.

How people got infected

In most reported cases the source was pirated software. The original Reddit poster acknowledged the likely culprit was a cracked game. This matches a long-standing pattern: downloading pirated, illegal or license-bypassed software puts your privacy, security and devices at risk.

What to do right now

  • Remove any recent, suspicious or pirated software from your computer.
  • Run a full malware scan of your system to find and remove any infostealer.
  • Sign back in to Claude and re-enter your payment details (affected users were logged out).
  • Review your billing, and contact Claude support if you see unusual charges that were not refunded.
  • Consider changing your password and enabling multi-factor authentication after your device is clean.

The takeaway

AI accounts are now a target for the same credential-theft malware that has long chased banking logins and crypto wallets. Keeping your device clean, and avoiding pirated software, is the first line of defense for your Claude account.

Source

Reporting: ZDNET, 7 September 2026. This is an informational summary, not security advice tailored to your situation.

Found something that needs updating?

Tools change quickly. Send a correction and include this page’s address.

Keep exploring.

View all