VentureBeat
Follow
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Infostealers are replaying stolen Claude session cookies into paid accounts, bypassing login page two-factor authentication and single sign-on. Anthropic flagged these as self-serve, card-billed accounts not governed by corporate identity providers. The company notified affected users, named six stealer families, signed out compromised accounts, and issued refunds. The primary risk lies in data exposure, not just the minor financial loss from usage. Commonly used infostealers like Vidar and LummaC2 were identified as culprits. A session cookie proves a user is already logged in, allowing attackers to impersonate legitimate users. Anthropic detected the theft by observing unusual usage patterns and drained limits. Vectors for infection include pirated software downloads and spoofed Claude download pages. The replayed session inherits the permissions of the legitimate user. This could grant attackers access to conversation history, uploaded files, and connected services like Google Workspace. Enterprise employees using personal AI subscriptions on work machines are a significant vulnerability. Many enterprise AI conversations occur through personal identities, not corporate ones. Security leaders are urged to add AI accounts to their incident response playbooks. Phishing attacks impersonating Anthropic's notification have also emerged. Counting personal AI subscriptions on managed devices and restricting OAuth grants is recommended. Moving heavy users to managed tenants and implementing session binding are crucial steps.