Anthropic boots users, wipes payment info to protect against malware attack

0
1
Anthropic boots users, wipes payment info to protect against malware attack


SOPA Images / Contributor/LightRocket via Getty Images

ZDNET’s key takeaways

  • Anthropic has alerted Claude users of an infostealer campaign.
  • Cybercriminals are now targeting usernames and passwords for AI platforms.
  • Refunds are being issued, but unless you clean up your device, it could happen again.

Anthropic has alerted some Claude users to a new infostealing malware that takes control of their sessions to steal their usage credits.

The aim of the campaign? To steal your usage.

Also: ‘Sophisticated’ AI swarm attacks are months away, OpenAI warns: What experts say businesses must do

Most infostealers, a family of malware, have traditionally targeted information such as account login credentials, sensitive data stored in browsers, financial records, and cryptocurrency wallets, all with the aim of conducting financial theft or fraud. 

We now need to add another dataset target to the mix: AI platform credentials. 

A user on Reddit posted a screenshot of the email they received from Anthropic, the company behind Claude, alerting them to a possible malware infection on their devices that compromised their Claude account. 

“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the email says.

Anthropic has signed out affected users from their accounts and removed their payment details. 

What’s the source?

According to the alert, infostealers targeting Claude are appearing on Windows and Mac PCs. There’s no current evidence that phones or tablets are involved. 

These infostealers, including Vidar, Lumma, StealC, and RedLine on Windows, alongside Atomic Stealer on a “small number of Macs,” are being used to quietly infiltrate Claude accounts and use up victim usage allowances — which could end up leading to extra usage credit charges. 

Also: Not just OpenAI – Anthropic says Claude’s hacking spree ‘falls short of ideal behavior’

These infostealers are quietly collecting login details, and Claude sessions appear to be among the targets of the theft. 

“If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause,” Anthropic says.

What Claude users should do now

Anthropic isn’t necessarily responsible for refunding unauthorized payments when malware infections result from users engaging in illegal activities, such as downloading cracked software or pirating material. 

The original Reddit poster, for example, admitted that the source of the infostealer was likely a cracked game, and as Anthropic says, it has “no reason to believe that this malware is related to Claude, installed through Claude, or related to anything [users] did with Claude.”

This user, and others involved in similar activities, are lucky that Anthropic is trying to protect their financial data and usage — and is also refunding any additional usage charges that appear unauthorized. 

Also: AI is finding bugs faster than humans can fix them: How enterprise security teams must adapt

The lesson here is simple and hasn’t changed from the early days of malware-ridden platforms like Limewire — you risk your privacy, security, and devices if you download cracked, pirated, or illegal software. 

Before doing anything else, you should remove any new, suspicious, or cracked software, and run a deep malware scan on your system to detect and wipe any infostealers lurking on your machine. 

Anthropic has signed out affected users, so if you are one, you will need to sign back in and re-add your payment details. If you notice any strange charges that haven’t been refunded, you can contact Claude support