Security IncidentNew

Threat actors steal session credentials from Anthropic Claude users

Dark Reading reports that threat actors deployed various infostealer malware variants to harvest session credentials and unlawfully access Claude accounts belonging to an unspecified number of Anthropic users. Claims are as reported; this summary makes no determination about accuracy or significance.

First detected
Aug 31, 2026
Last updated
Aug 31, 2026

Moderate confidence

Based on a single independent report.

Limited corroboration

1 reporting source

What does this mean?

Corroboration measures how many genuinely independent sources support the event. Confidence measures how reliable the available evidence appears.

Stable

No recent reporting has materially changed the known facts.

Follow this development to see meaningful updates as new evidence emerges.

Save keeps this for later. Follow tracks meaningful changes as new evidence emerges — it shapes your Following Feed, alerts, and digest eligibility, and doesn't promise an instant notification.

Why it matters

The campaign highlights the vulnerability of AI platform session tokens to endpoint credential theft, allowing adversaries to bypass standard authentication and potentially expose sensitive prompt data, chat histories, or proprietary information.

Coverage

Independent reporting

How this developed

  1. Aug 31, 2026

    1. Development detected

    2. New reporting added