Home / Technology / AI Account Hijacked Via Stolen Browser Data
AI Account Hijacked Via Stolen Browser Data
3 Sep
Summary
- Attackers used stolen browser data to access accounts.
- Malware on user PCs harvested active login sessions.
- Anthropic forced sign-outs and refunded unauthorized charges.

Anthropic has recently implemented forced sign-outs for user accounts and refunded unauthorized charges after attackers exploited stolen browser data. The security incident, disclosed via an email to affected customers, involved attackers using infostealer malware to harvest active login sessions directly from user PCs. This illicit access enabled unauthorized usage of Anthropic's services, rapidly depleting account limits and incurring fraudulent charges.
In response to this compromise, Anthropic took immediate action. The company forcibly signed out affected sessions, removed the payment card information on file for those accounts, and issued refunds for any extra usage charges incurred during the attack. While these measures aim to secure accounts and mitigate financial losses, Anthropic has alerted users that the malware on their personal computers will not be removed by these actions.