
Anthropic Forced Sign-Outs, Deleted Payment Cards, and Refunded Charges in Claude Session-Cookie Hijackings
Anthropic detected Claude sessions stolen by infostealer malware on users' own machines and unilaterally forced sign-outs, removed stored payment cards, and refunded unauthorized usage charges — without waiting for users to report the abuse. Six commodity malware families were blamed; Anthropic's infrastructure was not breached. The number of affected users was not disclosed.
Published