Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

The Malware Did Not Need Anyone's Password, and That Is the Whole Point

Anthropic is signing affected users out, removing saved payment methods and refunding unauthorised charges. What was stolen was session cookies from infected computers, the category of theft that walks straight past two factor authentication.

Outspoken Digest Technology Desk

Monday, August 31, 2026/3 min read

A single door key on a ring, photographed against black. A stolen session token works the same way, as a key already cut that opens the door without anyone being asked who is holding it
Photo: Pittigrilli via Wikimedia Commons (CC BY-SA 4.0)

Anthropic has told Claude users that a bad actor used ordinary infostealer malware to lift active login sessions from people's own computers, then used those sessions to get into their accounts and burn through their paid usage.

The company is signing affected users out, removing saved payment methods and refunding charges it identifies as unauthorised. That is a good response. It is also, in an important sense, the limit of what any service can do about this, and the reason why is the interesting part.

When you log in, the site does not remember your password. It hands your browser a token that says this browser has already proved who it is. That token is what keeps you logged in for weeks without typing anything.

An attacker who steals that token does not need your password. They do not need your second factor either, because the second factor was checked before the token was issued. Replaying a stolen session is arriving at a door that is already open.

This is why the framing matters. Almost every piece of security advice ever given to a consumer is about the login: pick a strong password, add two factor, move to passkeys. All of that hardens the door. None of it does anything about a thief who copies the key you were already holding.

We wrote about the migration away from passwords in the passkey transition, and everything in that piece still holds. It just does not cover this.

The malware is not special

That is the second thing worth absorbing. The families named in the reporting are commodity tools that have been circulating for years: Vidar, Lumma, StealC, RedLine and Acreed on Windows, and Atomic Stealer on macOS.

What they do is dull and comprehensive. They copy saved passwords, browser cookies and locally stored credentials from an infected machine and send them somewhere. They are sold to people who did not write them. There is no targeting in the sense that anyone chose you.

Which means the Claude accounts are not the story. They are a symptom that turned up because somebody noticed unusual usage on a metered product. If a machine gave up its Claude session, it gave up every other session in the same browser at the same moment: email, bank, cloud storage, work systems.

What the affected person actually has to do

Assume the machine is the problem, not the account.

Signing out of Claude everywhere invalidates the stolen Claude token. It does nothing about the malware that took it, which is still on the computer, still running, and will take the next token as soon as one is issued. Changing the password on a compromised machine hands the attacker the new password.

The order that works is: clean or rebuild the machine first, then change credentials from a device you trust, then revoke sessions everywhere. Doing those in the wrong order is a common and expensive mistake, and it feels like progress while achieving nothing.

For anyone who wants the honest version of the risk: an infostealer on a personal computer is a full compromise of everything that computer was signed into. Treat it that way rather than triaging one service at a time.

What this asks of the companies

Something more than sign-outs and refunds, eventually.

Session tokens have been the soft centre of web authentication for a decade, and the defences exist. Binding a session to a device, shortening its life for sensitive actions, watching for a session that suddenly appears from a different network and behaves differently: none of that is exotic. It is friction, and friction loses arguments to convenience until an incident makes the case.

The pattern is familiar from the other direction too. An automated attacker moving fast through a system that trusted a credential is what we picked apart in the lessons from an agent driven attack. Different mechanism, same underlying assumption: that whoever holds the token is who they say they are.

Anthropic's disclosure is the useful part here, and it deserves saying plainly. A company that says a bad actor got in through customers' own machines, names what it is doing about it, and refunds the charges is a company telling you something it could have quietly absorbed instead.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Technology Desk

Software, hardware, artificial intelligence and what they change for everyone else.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.