# AI Sessions Under Attack: Infostealer Targets Claude Users

> Data-stealing malware now hunts the active AI sessions of users, not just passwords. How to protect credentials and Claude sessions in your business.

**URL:** https://www.ciptadusa.com/blog/anthropic-users-infostealer-session-thefts  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-09-01  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-09/daily-appsec-20260901-014627.jpg  

## Article

Attackers no longer wait for a password to fall to brute force. Today they hunt at the moment a victim is least guarded: while a login session is still active. This week a report from Dark Reading revealed that users of Anthropic's AI assistant (Claude) were hit by infostealer attacks that stole sessions and credentials — not just passwords, but digital keys that were still valid.

## Summary
These attacks target the session cookies and authentication tokens of AI application users. With a still-valid key, an attacker enters an account as if they were the legitimate owner, bypassing many password protections.

## Background
An infostealer is malware that infects a device — through a malicious download, an email attachment, or a fake browser extension — and then drains data stored in the browser. It is not after passwords alone. Cookies, tokens, and saved autofill data unlock access to accounts that are currently logged in. A single infected device can leak many sessions at once.

## The Challenge
What makes this attack dangerous is that it targets the "session," not the password. Many applications with two-factor authentication still trust a session that was already verified. If that session is stolen, the second layer never gets a chance to reject it, because it looks like a legitimate login. For a business that relies on AI — chatbots, CRM, automation — a stolen account can mean customer conversations and internal data exposed.

## Approach
A few steps narrow the attacker's window:
1. Do not keep sessions on shared devices; use a separate browser profile for work accounts.
2. Enable re-auth session policies on applications that support them.
3. Use a password manager and hardware security keys for critical accounts.
4. Log out of devices you no longer use, right away.
5. Review your active sessions regularly and revoke anything suspicious.

## Implications
This threat drives home one point: security is not only about a strong password, but about how sessions and access are managed over time. The more a business puts AI into daily operations, the more valuable those credentials become to attackers.

## References
- [Anthropic Users Hit by Infostealer Attacks, Session Thefts (Dark Reading)](https://www.darkreading.com/cyberattacks-data-breaches/anthropic-users-infostealer-attacks-session-thefts)

**Protect your business AI assets with the right foundation.** Cipta Dua Saudara, a local software house in West Java, helps SMEs and institutions in Bandung, Bogor, Bekasi, Depok, Sukabumi, Cirebon, Karawang, and Banjar design secure authentication, access control, and AI automation — at fair prices and without vendor lock-in. Discuss your needs at [ciptadusa.com](https://ciptadusa.com).

---

*Markdown version of https://www.ciptadusa.com/blog/anthropic-users-infostealer-session-thefts — generated for AI agents and LLM crawlers.*
