News · curated 31 Aug 2026

Anthropic cracks down on hijacked user accounts mining AI tokens

Coverage timeline

31 Aug 2026theregister.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Anthropic's response highlights that AI platform accounts are now a monetization target for commodity infostealers, letting attackers burn victims' paid premium AI usage via stolen sessions.

Anthropic is responding to a wave of infostealer malware that steals Claude login credentials, session cookies, and MFA-bypass data to hijack accounts and freeload on victims' paid AI usage (token mining). Anthropic detected attempted API-based token theft, logged affected users out, and removed saved payment methods; the company stresses the malware is ordinary commodity infostealer activity unrelated to Claude itself and not agentic AI malware.