Anthropic is warning Claude users who may have malware on their PC

Anthropic is warning Claude users who may have malware on their PC

Anthropic has begun sending warnings to Claude users who may have malware on their PCs. The company says that the attacker may have gained access to their Claude accounts and used their limits.Anthropic is warning users over infostealer malware on their PCs.Anthropic seems to have detected that some Claude users may have malware on their PCs or laptops. The malware, known as infostealer, allows a hacker to gain access to all information and account details of a user. And in this case, it may also allow them to use the victim’s Claude account.The AI startup has sent warnings to some Claude users that may have the infostealer malware on their computers. This could have allowed a hacker to access Claude accounts and use up their limits. The company is signing affected users out of Claude and removing saved payment methods. Users may also receive refunds for charges Anthropic identifies as unauthorised.Anthropic says Claude is not linked to this attackA Reddit user who goes by the handle WorriedAssociate7029 shared the email they received from Anthropic on the subreddit ClaudeAI.In the email, Anthropic said it had “recently become aware of a bad actor” using common infostealer malware to steal Claude login sessions from people’s computers and then use those sessions to access accounts. The company explained that this was likely the cause of unusual usage of their Claude account. “If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause,” the email said. Anthropic states that while it is investigating the incident, it is likely that only computers were affected with infostealer malware. “Phones and tablets do not appear to have been involved,” the company said. “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude.” A screenshot of the Reddit post. Infostealer malware usually arrives through unofficial downloads or malicious apps and quietly copies saved passwords, browser login cookies, and credentials for other apps stored locally. This can even allow a hacker to bypass two-factor authentication and gain access to your accounts. The company said a user’s Claude session was likely one of many items collected by the malware, and that attackers had now started picking out Claude sessions and using them. Anthropic said the malware identified in the campaign so far includes Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer, or AMOS, on a small number of Macs.What can you do if you are affected?If you are one of the affected users, Anthropic clarifies that signing out of Claude does not remove the malware. “If it’s still on your computer, your next login session could be stolen the same way,” it said.Anthropic advises users to scan their computers for malware before using them again, then secure the email account linked to Claude by setting a new password, signing out of other devices, and enabling two-factor authentication. The company also suggests updating other passwords including for banking, work and cloud services, and checking card statements if payment details were stored in a browser. Only after those steps, it said, should you add a payment method again.This incident comes at a time when there is growing debate over the future of cybersecurity. While the infostealer malware is a common tactic, many are concerned that we may see more hacking attempts in the future as AI models become better. Recently, OpenAI disclosed that around 1,200 AI agents went rogue, 700 of which attempted to hack Hugging Face during an evaluation test. Whereas Anthropic and Meta have also disclosed incidents of their AI agents going rogue recently.- EndsPublished By: Armaan AgarwalPublished On: Aug 31, 2026 09:45 IST

Original Source

Read the full article at Indiatoday →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.