← All Briefings
Briefings


Anthropic Says Malware Is Draining Hijacked Claude Accounts

Anthropic told users this week that infostealer malware running on their PCs had harvested active Claude session tokens, handing attackers working logins that skip authentication entirely. A session token is not a password. It is the thing a password produces after login, which means the standard advice, "your credentials weren't compromised," is technically true and operationally useless: the attacker is already inside the session, spending the victim's usage allotment as their own.

The fix that actually closes this is server-side session revocation tied to device fingerprint changes, not a password reset, because the credential was never the thing that moved. Anthropic has not said how many accounts were hit or which infostealer family did it. Enterprise customers running Claude through SSO should ask their security team, this week, whether session tokens are bound to a single device or portable to whichever machine holds the cookie.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.