News · curated 31 Aug 2026
Anthropic cracks down on hijacked user accounts mining AI tokens
First reported theregister.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Anthropic's response highlights that AI platform accounts are now a monetization target for commodity infostealers, letting attackers burn victims' paid premium AI usage via stolen sessions.
Anthropic is responding to a wave of infostealer malware that steals Claude login credentials, session cookies, and MFA-bypass data to hijack accounts and freeload on victims' paid AI usage (token mining). Anthropic detected attempted API-based token theft, logged affected users out, and removed saved payment methods; the company stresses the malware is ordinary commodity infostealer activity unrelated to Claude itself and not agentic AI malware.