The Malware Did Not Need Anyone's Password, and That Is the Whole Point
Anthropic is signing affected users out, removing saved payment methods and refunding unauthorised charges. What was stolen was session cookies from infected computers, the category of theft that walks straight past two factor authentication.
Outspoken Digest Technology Desk
Monday, August 31, 2026/3 min read

Anthropic has told Claude users that a bad actor used ordinary infostealer malware to lift active login sessions from people's own computers, then used those sessions to get into their accounts and burn through their paid usage.
The company is signing affected users out, removing saved payment methods and refunding charges it identifies as unauthorised. That is a good response. It is also, in an important sense, the limit of what any service can do about this, and the reason why is the interesting part.
What a session cookie is, and why it beats a password
When you log in, the site does not remember your password. It hands your browser a token that says this browser has already proved who it is. That token is what keeps you logged in for weeks without typing anything.
An attacker who steals that token does not need your password. They do not need your second factor either, because the second factor was checked before the token was issued. Replaying a stolen session is arriving at a door that is already open.
This is why the framing matters. Almost every piece of security advice ever given to a consumer is about the login: pick a strong password, add two factor, move to passkeys. All of that hardens the door. None of it does anything about a thief who copies the key you were already holding.
We wrote about the migration away from passwords in the passkey transition, and everything in that piece still holds. It just does not cover this.
The malware is not special
That is the second thing worth absorbing. The families named in the reporting are commodity tools that have been circulating for years: Vidar, Lumma, StealC, RedLine and Acreed on Windows, and Atomic Stealer on macOS.
What they do is dull and comprehensive. They copy saved passwords, browser cookies and locally stored credentials from an infected machine and send them somewhere. They are sold to people who did not write them. There is no targeting in the sense that anyone chose you.
Which means the Claude accounts are not the story. They are a symptom that turned up because somebody noticed unusual usage on a metered product. If a machine gave up its Claude session, it gave up every other session in the same browser at the same moment: email, bank, cloud storage, work systems.
What the affected person actually has to do
Assume the machine is the problem, not the account.
Signing out of Claude everywhere invalidates the stolen Claude token. It does nothing about the malware that took it, which is still on the computer, still running, and will take the next token as soon as one is issued. Changing the password on a compromised machine hands the attacker the new password.
The order that works is: clean or rebuild the machine first, then change credentials from a device you trust, then revoke sessions everywhere. Doing those in the wrong order is a common and expensive mistake, and it feels like progress while achieving nothing.
For anyone who wants the honest version of the risk: an infostealer on a personal computer is a full compromise of everything that computer was signed into. Treat it that way rather than triaging one service at a time.
What this asks of the companies
Something more than sign-outs and refunds, eventually.
Session tokens have been the soft centre of web authentication for a decade, and the defences exist. Binding a session to a device, shortening its life for sensitive actions, watching for a session that suddenly appears from a different network and behaves differently: none of that is exotic. It is friction, and friction loses arguments to convenience until an incident makes the case.
The pattern is familiar from the other direction too. An automated attacker moving fast through a system that trusted a credential is what we picked apart in the lessons from an agent driven attack. Different mechanism, same underlying assumption: that whoever holds the token is who they say they are.
Anthropic's disclosure is the useful part here, and it deserves saying plainly. A company that says a bad actor got in through customers' own machines, names what it is doing about it, and refunds the charges is a company telling you something it could have quietly absorbed instead.
Published in The Outspoken Digest
Editorial desk
Outspoken Digest Technology DeskSoftware, hardware, artificial intelligence and what they change for everyone else.
Newsletter
The Digest, in your inbox
One edition, sent when it is ready. No noise, and your address is never passed on.
Read Next
More Technology →
Zuckerberg Said No to the Slowdown, Huang Called It a False Choice, and Amodei Told Dreamforce to Look at Its Own Record
Sep 17, 2026/3 min read

Falcon's 700th Flight, Europe's Plant-Fluorescence Satellite, and Djibouti Signs the Artemis Accords: A Weekend in Orbit
Sep 15, 2026/3 min read

iOS 27 Is Out With the New Siri, Which Is a Beta, in English Only, Not in the EU, and Only on an iPhone 15 Pro or Newer
Sep 15, 2026/3 min read

Anthropic, OpenAI and xAI Asked the Industry to Slow Down, the White House Said No, and Microsoft Wrote Rules
Sep 15, 2026/3 min read