Malware that steals your login without ever touching your password
On 30 August Anthropic started emailing Claude subscribers with an awkward message: we are signing you out, we have removed the payment card you had saved, and we are refunding charges you did not make. Their accounts had been taken over. Nothing had gone wrong at Anthropic's end. The break-in happened on the customers' own computers.
The tool was an infostealer, which has quietly become the most common way an ordinary person's accounts get taken. It arrives with an unofficial download or a cracked app, and one victim traced their infection to a pirated game. Then it copies everything worth copying: passwords saved in the browser, credentials from other programs, and, most usefully for the attacker, session cookies. A session cookie is the token your browser keeps after you log in, the thing that stops a site asking who you are on every page. Steal it and you are already inside. No password prompt. No two-factor code. The families named in the reporting are the usual crowd: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs.
Anthropic was blunt about where the fault lies, telling users it had "no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude." That is the part to sit with. If a stealer took your Claude cookie, it took your email cookie too, and your bank's, and your shop's. Anthropic can only sign you out of Anthropic.
Order matters if this ever lands on you. Clean the machine first, because changing passwords on an infected PC just hands over the new ones. Then reset your email password, turn two-factor on, and use the "sign out everywhere" option on every account that has one. That last step is what kills a stolen cookie, and it is the step almost everyone skips. Tendvane is not an antivirus and will not remove a stealer, but its Privacy and accounts check does show which accounts are signed in on the PC, which is a sensible way to build that list.