Stolen Claude session cookies can reportedly be replayed into paid accounts and used to reach corporate Gmail, according to VentureBeat. The outlet says infostealers used the cookies without ever hitting the login page where two-factor authentication would normally apply. The accounts Anthropic flagged were not enterprise-managed seats, VentureBeat reports. They were card-billed, self-serve paid accounts — the kind of account population that, according to the report, is not governed by a corporate identity provider. That distinction matters because corporate identity systems are typically where companies enforce access rules for managed software. In VentureBeat’s account, the exposure came through self-serve accounts outside that control plane, and through grants the outlet describes as ones no IT admin can revoke. The cluster contains only VentureBeat’s report, so the precise scope is still developing. The available summary does not provide the number of accounts involved, the timing of Anthropic’s flags, or the exact grant path into Gmail. For now, the concrete takeaway is narrow but important: VentureBeat says attackers did not need to defeat the login page’s two-factor authentication if they already had replayable Claude session cookies for affected paid accounts. Who benefits: Attackers with infostealer data benefit from any path that lets them reuse authenticated sessions rather than trigger fresh login challenges. Who's exposed: Organizations whose employees use card-billed, self-serve Claude accounts tied to corporate Gmail are the exposed population identified in the VentureBeat report.