Claude Accounts Targeted in Large-Scale Credential Theft Campaign
Summary
Anthropic reportedly forced many Claude users offline and removed saved payment methods after an account-compromise campaign. Information-stealing malware allegedly captured passwords, cookies, and active session credentials, allowing attackers to bypass 2FA without relying on a new password. The stolen accounts and Claude quotas were reportedly resold through unofficial services or converted into API keys for token-based profit. Users are advised to revoke all active sessions, clear browser data, avoid unofficial software, and reinstall systems confirmed to be infected.