The Malware Did Not Need Anyone's Password, and That Is the Whole Point
Anthropic is signing affected users out, removing saved payment methods and refunding unauthorised charges. What was stolen was session cookies from infected computers, the category of theft that walks straight past two factor authentication.
Outspoken Digest Technology Desk
Monday, August 31, 2026/3 min read

Anthropic has told Claude users that a bad actor used ordinary infostealer malware to lift active login sessions from people's own computers, then used those sessions to get into their accounts and burn through their paid usage.
The company is signing affected users out, removing saved payment methods and refunding charges it identifies as unauthorised. That is a good response. It is also, in an important sense, the limit of what any service can do about this, and the reason why is the interesting part.
What a session cookie is, and why it beats a password
When you log in, the site does not remember your password. It hands your browser a token that says this browser has already proved who it is. That token is what keeps you logged in for weeks without typing anything.
An attacker who steals that token does not need your password. They do not need your second factor either, because the second factor was checked before the token was issued. Replaying a stolen session is arriving at a door that is already open.
This is why the framing matters. Almost every piece of security advice ever given to a consumer is about the login: pick a strong password, add two factor, move to passkeys. All of that hardens the door. None of it does anything about a thief who copies the key you were already holding.
We wrote about the migration away from passwords in the passkey transition, and everything in that piece still holds. It just does not cover this.
The malware is not special
That is the second thing worth absorbing. The families named in the reporting are commodity tools that have been circulating for years: Vidar, Lumma, StealC, RedLine and Acreed on Windows, and Atomic Stealer on macOS.
What they do is dull and comprehensive. They copy saved passwords, browser cookies and locally stored credentials from an infected machine and send them somewhere. They are sold to people who did not write them. There is no targeting in the sense that anyone chose you.
Which means the Claude accounts are not the story. They are a symptom that turned up because somebody noticed unusual usage on a metered product. If a machine gave up its Claude session, it gave up every other session in the same browser at the same moment: email, bank, cloud storage, work systems.
What the affected person actually has to do
Assume the machine is the problem, not the account.
Signing out of Claude everywhere invalidates the stolen Claude token. It does nothing about the malware that took it, which is still on the computer, still running, and will take the next token as soon as one is issued. Changing the password on a compromised machine hands the attacker the new password.
The order that works is: clean or rebuild the machine first, then change credentials from a device you trust, then revoke sessions everywhere. Doing those in the wrong order is a common and expensive mistake, and it feels like progress while achieving nothing.
For anyone who wants the honest version of the risk: an infostealer on a personal computer is a full compromise of everything that computer was signed into. Treat it that way rather than triaging one service at a time.
What this asks of the companies
Something more than sign-outs and refunds, eventually.
Session tokens have been the soft centre of web authentication for a decade, and the defences exist. Binding a session to a device, shortening its life for sensitive actions, watching for a session that suddenly appears from a different network and behaves differently: none of that is exotic. It is friction, and friction loses arguments to convenience until an incident makes the case.
The pattern is familiar from the other direction too. An automated attacker moving fast through a system that trusted a credential is what we picked apart in the lessons from an agent driven attack. Different mechanism, same underlying assumption: that whoever holds the token is who they say they are.
Anthropic's disclosure is the useful part here, and it deserves saying plainly. A company that says a bad actor got in through customers' own machines, names what it is doing about it, and refunds the charges is a company telling you something it could have quietly absorbed instead.
Published in The Outspoken Digest
Editorial desk
Outspoken Digest Technology DeskSoftware, hardware, artificial intelligence and what they change for everyone else.
Newsletter
The Digest, in your inbox
One edition, sent when it is ready. No noise, and your address is never passed on.
Read Next
More Technology →
A Federal Judge Has Told the Pentagon That National Security Is Not a Blank Cheque
Aug 30, 2026/3 min read

They Have Photographed the Star Hiding Inside Betelgeuse, and They Still Are Not Certain It Is There
Aug 28, 2026/4 min read

Physicists Made Entangled Photons Out of Ordinary Sunlight, Which Was Supposed to Require a Laser
Aug 25, 2026/4 min read

Nvidia Is Putting AI Server Prices Up by More Than Fifteen Per Cent, and the Chips Are Not the Reason
Aug 25, 2026/3 min read