Anthropic has started forcing some Claude users out of their accounts, deleting their saved credit cards, and refunding charges they never made. The cause was not a breach at Anthropic. It was malware already sitting on the victims' own computers.
That malware, six known families including Vidar, Lumma, StealC, RedLine, Acreed and Atomic Stealer on Mac, does not target Claude specifically. It is the kind of general-purpose thief that arrives bundled with a cracked game or a pirated app download, and it copies whatever passwords and login cookies it finds sitting in your browser.
A login cookie is the small file your browser keeps after you sign in, so a website does not ask for your password again every time you click something. If an attacker steals that file, they can load it into their own browser and step straight into your account, already logged in. No password needed, no two-factor code needed, because the website thinks you are just continuing where you left off.
Anthropic says both Windows and Mac users were affected, and the attackers did not hack Claude itself. They hacked victims' personal computers first, then picked the Claude sessions out of everything else the malware had already stolen. Once inside, the attackers could burn through a victim's usage limits and put unauthorized charges on any card saved to the account, which is why Anthropic pulled every stored card and issued refunds rather than just logging people out.
None of that fixes the actual problem. Anthropic can close every stolen session it finds, but if the malware is still running on a customer's laptop, the next login produces a fresh cookie and hands it right back to the attacker. Anthropic's own advice is direct: remove the malware first, then change your email password, turn on two-factor authentication, and only then add a payment card back.
This is not an isolated incident. Security researchers at CrowdStrike and Palo Alto Networks have described a market for stolen AI logins for over a year, where accounts for Claude, ChatGPT and Gemini get pooled and resold through what researchers call transfer stations, at a fraction of the real subscription price. Palo Alto has traced at least one hijacked account to close to a million dollars in unauthorized usage before it was caught.
For a business, the real exposure is not the stolen usage credits, it is what sits inside the account. A Claude for Work account can hold uploaded files, project data and past conversations, and a hijacked session hands all of that to whoever is holding the stolen cookie. Infostealer infections have hit roughly two out of every three organizations at least once in the past five years, which makes an employee's laptop a more realistic entry point into a company's AI accounts than any weakness in Anthropic's own systems.
The fix has nothing to do with Anthropic and everything to do with basic device habits: keep antivirus current, avoid pirated software and cracked downloads, and treat a company AI login the way you would treat online banking, worth locking down with its own password and two-factor authentication instead of sitting logged in forever in a browser tab.