Back to news
policyAnthropic2026-08-31

Claude suffers mass account-takeover incident, active users forcibly logged out

On Aug 31, Anthropic hit an account-security incident: info-stealer malware hijacked active sessions, large numbers of users forcibly logged out and payment methods wiped.

On August 31, Anthropic suffered an account-security incident. The cause was infostealer malware that hijacked a batch of active session tokens, leading to large numbers of Claude users being forcibly logged out without warning and having their payment methods wiped.

Anthropic is actively signing out affected sessions, removing stolen card numbers, and refunding unauthorized charges, and has urged users not to download pirated software. The company simultaneously updated user security guidance, requiring all affected users to reset passwords and enable hardware security keys or passkey-based multi-factor authentication.

The incident again highlights that AI platform accounts have become high-value attack targets. Claude Pro, Max, and Team users have high-value accounts due to bound cards and annual subscription amounts far exceeding traditional SaaS services, and infostealer black-hat actors have placed Claude and ChatGPT on their priority hunting lists.

ClaudeAnthropic账号安全盗号