Anthropic cracks down on hijacked user accounts mining AI tokens
- ID
- 19977
- Status
- summarized
- Published
- 01 Sep 2026, 12:03 AM
- Fetched
- 01 Sep 2026, 4:50 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/31/anthropic-cracks-down-on-hijacked-user-accounts-mining-ai-tokens/5293461
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 6.5
- Created
- 01 Sep 2026, 4:50 AM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
Anthropic is detecting infostealer malware campaigns that steal Claude session cookies and credentials, allowing attackers to freeload on victims' paid Claude usage. In at least one confirmed case, Anthropic proactively logged the user out and deleted their stored payment method after detecting attempted fraud via the API. Anthropic emphasized this is commodity infostealer malware, not a Claude-specific vulnerability.
Why it matters
If you use Claude with a saved payment method and Google SSO, your account is a target for session-cookie theft via standard infostealer malware. Remove saved payment methods when not actively needed, periodically revoke active sessions, and treat your Claude session cookies as financially valuable credentials.
Discussion angle
How should AI API providers balance proactive fraud detection (like deleting payment methods without consent) against user friction, and what session hygiene should builders using paid AI APIs adopt as standard practice?