Security/ anthropic · claude · security · malware

Anthropic starts auto-signing out Claude users after session theft

Anthropic now force-logs Claude users out after malware apparently siphoned active login sessions from infected PCs.

Anthropic is now automatically signing Claude users out of sessions that infostealer malware appears to have stolen.

The company says infostealer malware apparently harvested active Claude login sessions directly from infected PCs, letting attackers reuse them without needing a password or two-factor code. In response, Anthropic has started force-logging out affected sessions rather than waiting for users to notice something is wrong. The move treats a stolen session token the same way a bank treats a stolen card number: kill it before it gets used. Anthropic has not detailed how many accounts were affected or how it detects a compromised session.

Session-token theft has become one of the more boring but effective ways to break into accounts, since it skips the login screen entirely: no password to guess, no MFA prompt to bypass. Anthropic pushing an automatic kill switch acknowledges that user vigilance alone won't catch this kind of theft. For a company selling AI tools to businesses that increasingly hand it sensitive data, that's not just a security feature. It's table stakes.

Infostealers have plagued browsers and cloud dashboards for years; Claude just joined the list of places they've been caught working.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →