Some users of Anthropic's AI Claude are reporting that the company logged them out of their Claude accounts. That's for their own protection: their credentials were stolen using infostealers, and cybercriminals tried to abuse the access.
Logging out and removing payment methods as an immediate measure
This can be seen, for example, in a thread on Reddit. Anthropic sent affected users an email indicating they need to take action because their Claude access was affected by an issue. The company states that, as an immediate measure, it logged users out of their accounts and removed the stored payment method. Affected users therefore need to log back in and add a credit card again.
Warning about token theft
In the email, Anthropic further explains that malicious actors used an infostealer to steal Claude login sessions from computers and used them to access accounts and consume the available tokens. The accounts of the email recipients were affected, which is why Anthropic took these steps for them to prevent further abuse by cybercriminals. If your usage limits look like they were refilled and then drained, while you yourself weren't using the service at all, that's likely the cause.
Anthropic is continuing to investigate the incident, but the evidence points to affected users' computers being infected with an infostealer. Tablets and smartphones don't appear to be affected. The infostealers identified in the campaign so far include Vidar, Lumma, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer on a smaller number of Macs.
What affected users should do now
Victims should scan their systems for malware. After removing the infostealer, you should also set a new password for your email account, log out sessions on other devices, and enable two-factor authentication. Ideally, you should also renew any passwords stored in your browser and check your bank statements and credit card usage if applicable. Only after taking these security steps should you re-enter payment information into your Claude account.
On Reddit, the thread's author writes that their credentials and session cookies were apparently stolen from the Chrome browser, even though they already use two-factor authentication. They're nonetheless grateful to Anthropic for apparently responding quickly and minimizing the resulting damage.