Skip to content

Anthropic

Disclosed Aug 31, 20263 weeks agoUnverified

Infostealer-stolen session cookies used to hijack Claude accounts

Anthropic emailed users and signed them out after finding their Claude login sessions had been stolen by infostealer malware such as Vidar, Lumma, StealC, RedLine, Acreed and Atomic Stealer; it removed saved payment methods and refunded unauthorized Claude charges.

What is known

People affectedNot stated in the sources we have
DisclosedAug 31, 2026
AttackHacking
Data exposedCredentials and tokens, Payment cards, Prompts and chats
SectorAI · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalAug 31

Other breaches at Anthropic

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Anthropic

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.