Anthropic has been automatically signing some Claude users out, removing saved payment cards, and refunding charges after attackers used stolen browser data to abuse their accounts, according to Engadget. The report cites an Anthropic email sent to affected users last week and later shared publicly on Reddit, with SecurityWeek also reporting on the incident. The company’s explanation, as reported by Engadget, points to infected customer devices rather than a breach of Anthropic’s own systems. Anthropic reportedly told affected users that infostealer malware had harvested active Claude login sessions from their computers. Once those sessions were in an attacker’s hands, the attacker could use Claude under the victim’s account, burn through usage limits, and potentially trigger unauthorized charges. The mechanism matters because this was not described as a conventional password compromise. Engadget reports that the malware copied Claude session cookies — browser tokens that keep a user logged in after authentication. If an attacker can replay one of those cookies, they can pick up an already-authenticated session without necessarily triggering a fresh password or two-factor authentication challenge. Anthropic identified six malware families tied to the hijacked sessions, according to the report: Vidar, Lumma, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer, also known as AMOS, on a small number of Macs. Engadget notes that these are general-purpose infostealers rather than malware built specifically to target Claude. They are commonly associated with malicious downloads and are designed to collect saved passwords, cookies, and other browser-held credentials. Anthropic’s response, as described in the email, was to force sign-outs for affected sessions, remove saved payment methods, and refund extra usage charges it connected to the suspicious activity. That combination addresses the account-side problem — cutting off stolen sessions and limiting additional billing — but it does not clean the infected device. Anthropic reportedly told users that the malware must be removed before they log back in. The recommended recovery path is therefore sequential: remove the malware, secure the email account attached to Claude with a new password and two-factor authentication, and only then re-add payment methods to Claude. Engadget also frames the incident as part of a broader market for stolen AI-service access. It cites CrowdStrike executive Adam Meyers telling Axios in August that criminals are trafficking hijacked credentials for Claude, ChatGPT, and Gemini, and points to Palo Alto Networks’ Unit 42 findings on proxy services that pool stolen credentials and resell access to AI services below retail cost. For AI vendors, the economics are direct: every prompt carries a compute cost, and a hijacked session can shift that cost onto the platform or the victim’s payment card. For users, the incident is a reminder that multifactor authentication helps at login but may not stop an attacker who has already stolen a valid browser session token from an infected machine. Who benefits: Users benefit from Anthropic revoking affected sessions, removing saved cards, and refunding extra charges tied to the reported abuse. Who's exposed: Claude users with infected PCs or Macs are exposed, especially if their browsers store active sessions and their accounts have payment methods attached. Anthropic is also exposed to compute costs from hijacked sessions and customer-support burden from unauthorized usage claims.