Home / Technology / AI Accounts Compromised Via Stolen Session Cookies
AI Accounts Compromised Via Stolen Session Cookies
2 Sep
Summary
- Infostealers bypass two-factor authentication using stolen session cookies.
- Anthropic identified six malware families used in the attack.
- Affected accounts were direct-billed, self-serve without corporate identity providers.

AI accounts are vulnerable to attackers who exploit stolen session cookies, bypassing essential security measures like two-factor authentication. Infostealer malware, including families like Vidar and LummaC2, has been used to replay these cookies, granting access to accounts without user interaction at the login page. Anthropic disclosed that the affected accounts were primarily self-serve, card-billed users, indicating a lack of corporate identity provider governance.
This method of attack targets the proof of a completed login, essentially hijacking an active session. By replaying stolen cookies, attackers gain access to everything the legitimate user could reach within the AI service. While Anthropic has taken steps like signing out affected users and refunding charges, the underlying malware remains on infected devices, posing a continued risk for future session theft.
The security implications extend to connected services, as compromised sessions could grant unauthorized access to uploaded files, conversation history, and linked applications. This raises concerns about data exfiltration and unauthorized actions within integrated platforms, especially when personal AI subscriptions are linked to work-related services like Google Workspace.