Infostealers drain paid Claude accounts, Anthropic warns

If your Claude usage limit looked like it refilled and then drained again while you were nowhere near the keyboard, somebody else may have been using it. That is the symptom Anthropic described to affected customers in a warning email, one copy of which an affected user shared publicly.

The company says a bad actor has been using common information-stealing malware to take Claude login sessions from people's computers, then using those sessions to reach the accounts and consume their usage. Anthropic has been signing the affected sessions out, removing the payment card saved on those accounts, and refunding charges it identifies as unauthorized.

Nothing about this is a compromise of Claude itself. Anthropic states it has no reason to believe the malware was related to Claude, installed through Claude, or connected to anything the user did with it. The infection came from somewhere else on the machine; Claude was simply one of the logged-in services it found there.

A stolen session skips the password entirely

This is worth understanding because it defeats the advice most people have already followed. When you log in to a site, your browser is handed a session cookie, a small token that proves you already authenticated. Every subsequent request rides on that token rather than on your password.

Malware that copies the token copies the proof. The attacker never needs the password, and never needs the second factor either, because the multi-factor check happened before the token was issued. Strong credentials and an authenticator app do not help once the browser session itself has been taken off the machine.

Why a stolen session is worth real money

Paid Claude plans can offer usage credits. When a subscriber hits their plan's session limit, they can keep going through consumption-based billing at standard API rates, which the user has to enable, configure with a monthly spending limit or unlimited spending, and prepay for. There is also an auto-reload option that buys more prepaid credits whenever the balance falls below a threshold.

Put a hijacker inside that arrangement and the arithmetic is obvious. They can burn the plan's included allowance, then any credits sitting in the balance, and if auto-reload is switched on they can keep triggering further purchases on the victim's card. The likeliest motive is simply free access to paid AI capacity. Stolen capacity of that kind could support other criminal work, from drafting scam content to analysing stolen data, though Anthropic points to its own safeguards and abuse monitoring and says it has disrupted accounts used for malicious activity.

Clean the machine before you change anything

The order of these steps matters more than the steps themselves, because changing a password on an infected computer just hands the new one over too.

If usage still moves while Claude sits idle, or an unrecognised charge appears after all of that, Anthropic asks users to contact usersafety[at]anthropic.com.

The warning was reported by Malwarebytes from the notification email Anthropic sent to affected customers. It is a plain reminder that the AI subscription is now an asset worth stealing on its own terms, alongside campaigns that have used the brand as bait, including a fake Claude Code guide that dropped a six-stage Mac stealer. Anthropic's own research into what its models can reach has focused on the model. This one is about the account.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions