Security News

Anthropic Alerts Claude Users to Infostealer Malware Risk

Security Week · 31 Aug 2026
Key Takeaway Ensure staff devices have up-to-date antivirus and endpoint protection, and encourage unique, regularly rotated passwords with multi-factor authentication for all cloud and AI service accounts.

AI company Anthropic has begun warning users of its Claude chatbot that some accounts may have been compromised by infostealer malware. In response, the company is proactively logging affected users out of their accounts and stripping stored payment information to prevent unauthorized use of paid subscriptions.

Infostealer malware is designed to quietly harvest saved passwords, session tokens, and payment details from infected devices, often without the victim noticing until the stolen data is used or sold. When such malware compromises a user's device, credentials for online services like Claude can end up in the hands of criminals, who may then access the account, run up charges, or misuse connected services.

Anthropic's response reflects a broader trend where infostealer infections on customer devices, rather than breaches of the service provider itself, are the root cause of account takeovers. This means the security gap often exists on the user's own computer rather than within Anthropic's systems.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.