📣 Send us your press release
Site updates every 15 minutes
Technology

Stolen Claude session cookies bypassed IT security into corporate Gmail

Infostealers replayed stolen Claude session cookies into paid accounts, bypassing 2FA and SSO. This exposed corporate data like Gmail through personal AI accounts.

2 September 2026
Stolen Claude session cookies bypassed IT security into corporate Gmail

Malware designed to steal information has successfully replayed stolen Claude session cookies, granting access to paid accounts without requiring any login or two-factor authentication.

Anthropic identified these attacks by monitoring usage meters where accounts were being consumed unexpectedly. The company notified affected users, signed out the compromised sessions, removed saved payment methods, and refunded fraudulent charges.

Six families of stealer malware were identified, including Vidar, LummaC2, and RedLine for Windows, and Atomic Stealer for a small number of Macs. These malware types are known to collect browser session cookies along with saved passwords.

The primary vulnerability lies with card-billed, self-serve accounts that do not fall under corporate identity providers. While enterprise accounts with SSO are protected, personal or team accounts can be compromised, potentially exposing sensitive corporate data such as Gmail inboxes or cloud storage via connected apps.

Original source: venturebeat.com