Technology newsroom
Warning to Claude AI Users! 🤖 Infostealer Malware Stealing Login Sessions, Draining API Credits
Anthropic has issued a warning to Claude AI users regarding Infostealer malware, which is actively stealing login sessions from users' computers. This allows hackers to access accounts and completely drain API credits. The company advises users to change their passwords and enable two-factor authentication (2FA) to enhance security.
📌 Key Highlights:
- Anthropic, the developer of Claude AI, has issued a warning to users about Infostealer malware targeting login sessions.
- Hackers can use stolen sessions to access accounts, read chat histories, and deplete users' API credits, leading to financial damages.
- Anthropic has invalidated stolen sessions and notified affected users, advising them to promptly change passwords and enable 2FA.
Anthropic, the AI research and development company behind Claude, a major competitor to ChatGPT, has sent email notifications to some users concerning an ongoing cyber threat. It was discovered that malicious actors are using Infostealer malware to gain unauthorized access to users' Claude accounts.
💻 How Does the Attack Work?
This attack did not originate from a direct breach of Anthropic's systems but occurred on users' own computers. When a user's machine becomes infected with Infostealer malware, such as Lumma, Redline, or Raccoon, these malware programs steal critical information stored in web browsers. This includes cookies and session tokens used for login authentication. Once hackers obtain this information, they can impersonate the account owner and immediately access Claude without needing a password.
💸 Impact
Once hackers gain access to an account, they can view all of the user's conversation history. More severely, they can deplete all purchased API quotas or credits, causing direct financial damage, especially for developers or businesses relying on Claude's API for their work.
🛡️ Anthropic's Response and Recommendations
Anthropic states that its team detected this suspicious activity and has already invalidated or revoked the stolen sessions to cut off hacker access. Email notifications have also been sent directly to affected users. The company advises all users, especially those who received a notification email, to take the following immediate actions:
1. Immediately change your Claude account password.
2. Enable Two-Factor Authentication (2FA) to add an extra layer of security.
3. Scan your computer with up-to-date Antivirus software to detect and remove Infostealer malware from your machine.
This incident serves as a crucial reminder that personal device security is paramount. Even if online services have robust security, a user's computer infected with malware still poses a risk of critical data theft.
💬 Have you checked the security of the computer you use for work? And have you enabled 2FA for all your online services?