Infostealers bypassed Claude's two-factor authentication entirely by replaying stolen browser session cookies into paid accounts. Anthropic confirmed the campaign in notification emails to affected users, named six malware families: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer on Macs. The company signed accounts out, removed saved payment methods, and refunded fraudulent charges. It has not disclosed how many accounts were hit.
The refund is not the story. A replayed session inherits every permission the legitimate session held, including Claude connectors authorized to read Gmail inboxes, search Drive folders, and take write actions inside connected services. Anthropic's help center confirms that read and search operations run without user approval. LayerX data cited in Akamai's enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude accounting for 61% of that share. No corporate identity provider governs those accounts, and no tenant administrator can sign them out. The Workspace or Entra admin who could pull the underlying OAuth grant rarely knows it exists.
The full article is worth reading for three reasons: the FakeAgent malvertising campaign that pushed SectopRAT through a spoofed claude.ai Artifact to 29 organizations in two days, CrowdStrike's documented LLMjacking case that fired nearly 200,000 API requests through a compromised account in two minutes, and Common Room architect Tom Kleinpeter's account of why he rejected local MCP servers entirely to avoid creating the same credential exposure. The attack surface here is not piracy. It is enterprise employees using personal Claude subscriptions on work machines with live authorizations into corporate infrastructure.
[READ ORIGINAL →]