← Back to Tech & Science

Cybercriminals Hijack Claude Accounts via Infostealer Malware to Inflate User Charges

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

Global users of the artificial intelligence platform Claude are facing a new wave of financial and security threats as cybercriminals deploy infostealer malware to hijack active browser sessions. The attack, identified on Sept. 1, 2026, involves malicious software designed to extract authentication tokens from victims' browsers, allowing attackers to bypass login credentials and take control of paid accounts.

The primary objective of the campaign is to consume paid usage capacity at the expense of the account holders. Once the malware successfully steals a session cookie or token, attackers can immediately begin generating high-volume queries on the platform. This unauthorized activity rapidly depletes the victim's subscription credits or incurs significant overage charges on their billing statements. The financial impact varies depending on the user's plan limits and the volume of requests generated by the intruders before detection.

Beyond immediate financial loss, security experts warn that the compromised sessions create a gateway for more sophisticated threats. By gaining access to authenticated accounts, cybercriminals can potentially harvest sensitive data entered into chat interfaces, including proprietary business information, personal identifiers, or confidential documents uploaded by users. Furthermore, the hijacked accounts may be utilized to launch social engineering campaigns against other users or to conduct follow-on attacks within the platform's ecosystem.

The infostealer malware operates silently in the background of infected devices, often entering systems through malicious email attachments, compromised software updates, or drive-by downloads on unsecured websites. Unlike traditional credential theft that requires a password reset to be effective, session hijacking allows attackers to remain logged in even if the user changes their password, as the stolen token remains valid until it expires or is explicitly revoked by the platform.

Affected users are advised to immediately terminate all active browser sessions and revoke access tokens through their account security settings. Changing passwords alone may not be sufficient if the session token has already been exfiltrated. Users should also scan their devices for known infostealer variants and monitor billing statements for unauthorized charges.

As of now, the geographic origin of the attack campaign remains unconfirmed, with indicators suggesting a distributed network of actors operating across multiple regions. The full scale of the compromise is still being assessed, as many victims may not realize their accounts have been breached until they receive unexpected invoices or notice unusual activity logs. Security researchers are currently working to identify the specific malware variants involved and develop signatures to detect future iterations of the campaign.

The incident highlights the growing sophistication of threats targeting AI services, where the value of computational power and data access drives new criminal methodologies. Whether this represents an isolated surge in activity or the beginning of a sustained campaign against AI platforms remains unclear as investigators continue to analyze the scope of the breach.

Discussion

0 / 2000