Your password and two-factor code might not be enough to keep hackers out of your AI account anymore. Here’s why.

Cybercriminals have been reportedly stealing the login sessions of people who use Claude, the artificial intelligence (AI) chatbot made by Anthropic, according to Cyber Security News. Instead of guessing passwords, the attackers use malicious software, known as infostealer malware. It lifts the small digital “keys” that websites use to recognize a client who has already logged in. That means a hacker can slip into someone’s account without ever typing a password or facing a two-factor prompt, because the account already looks authenticated on the chatbot end.
Claude is a popular conversational AI tool, similar to ChatGPT. By rough estimations, about 50 million people use it each week for writing, coding, and research, either through a website or a downloadable app. Anthropic is the company that builds it. Every time someone logs into an online account, the tool creates a “session”. It lets the site remember that person is signed in without asking for a password again and again. If that session data is stolen, a criminal can essentially borrow someone’s identity online for as long as the session stays valid.
According to the report, several well-known families of infostealer malware, including Vidar, Lumma, StealC, RedLine, and Acreed on Windows computers, along with Atomic Stealer on Apple’s macOS, have been quietly collecting saved passwords, browser cookies, and other login data from infected devices. In the emails sent to affected Claude users, Anthropic says it noticed something was wrong after spotting unusual patterns, i.e. paid usage on some accounts kept being consumed even after the actual owners had stopped using the service. That was a clear sign someone else was logged in.
A second, related scheme report showed how attackers twisted Claude’s own platform against its users. Cybersecurity firm Huntress found that, over two days in late July, criminals bought sponsored search ads that appeared when people searched for the Claude desktop application. Clicking the ad led to a fake installer hosted on Claude’s own legitimate website domain, which then installed a separate strain of malware capable of stealing passwords, cookies, files, and even payment card details. Huntress said at least 29 organizations were affected and roughly 7,100 people downloaded the fake installer before Anthropic took the page down.
Researchers also flagged another new trick. Hackers are hiding harmful instructions inside ordinary-looking configuration files used by Claude’s automated tools, which can silently reinfect a device even after it has been cleaned.
In response to the latest cybersecurity infringement, Anthropic has reportedly informed the affected users by email. The comapny has also been signing affected users out of their accounts, removing saved payment methods, and refunding fraudulent charges. However, the company has cautioned that these steps do not remove malware already sitting on someone’s computer or phone. Therefore, a freshly logged-in account could be compromised again unless the underlying infection is dealt with separately.
Security experts recommend running a full malware scan before logging back into any AI account, changing passwords with two-factor authentication enabled, and treating unexpected links or suggested commands with the same caution as suspicious email attachments.


