The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Infostealers Hijack Claude Sessions to Drain Credits and Steal Data

The Perimeter Desk
2026-08-31
# Infostealers Hijack Claude Sessions to Drain Credits and Steal Data The latest warning from Anthropic isn't about some sentient AI breaking its chains or a complex prompt injection attack. It is much more boring than that. Attackers are using standard infostealer malware to grab active session cookies from browsers, allowing them to step right into a user's Claude account without ever needing a password. For the ten-person shop, this is a reminder that your fancy new AI tools are only as secure as the browser they run in. If you have an employee using Claude to summarize sensitive client contracts or draft internal strategy docs on a laptop that also downloads "free" PDF converters and cracked software, you don't have an AI security problem. You have a hygiene problem. The claim here is that we are focusing on the wrong risks with AI. We worry about the model hallucinating or leaking training data, but the actual vulnerability is the session token sitting in a Chrome cache. The implication is simple: once those cookies are stolen, MFA doesn't matter because the attacker isn't logging in—they're already in. Some might argue that enterprise-grade endpoint protection should stop the infostealer before it ever touches the browser. That sounds great in a sales pitch, but in a small office, "endpoint protection" is often just whatever came pre-installed on the laptop three years ago. The reality is that session hijacking is the path of least resistance for criminals because it bypasses the most common defenses we're told to trust. The second-order effect here hits the budget. These attackers aren't just stealing data; they are draining usage limits. For a small firm on a tiered plan, you might see your monthly credit allotment vanish in forty-eight hours because a bot in another country is using your account to scrape data or run heavy workloads. You're paying for the compute while the attacker gets the output. While AI gets the headlines, the wire is currently dominated by the sheer volume of records being dumped into the wild. We are seeing a massive cluster of breaches hitting disparate sectors. CareCloud has seen 3.75 million Americans affected. CarGurus reports 12.5 million accounts exposed. Manchester Airports Group has leaked data on 8.7 million customers. When a company like Manchester Airports loses nearly 9 million records, they hire a global forensics firm and spend six figures on a PR agency to manage the fallout. For a small business owner, the "defense" is different. You aren't the one leaking the data; you're likely the one whose data was in those lists because you used their services. The gap between enterprise and small-firm defense isn't just about money—it's about visibility. The big players know exactly what was taken within days. You find out three months later via a notification email that you can't tell if is a scam or a legitimate warning. If you use third-party cloud providers for billing, CRM, or logistics, you have to assume the data is already gone and focus on the only thing you actually control: your own passwords and your recovery process. The sector stats reflect this. Government remains the primary target, ranking #1 this week with 252 stories, followed by Technology at #2 with 242 stories. It's a sustained assault on the plumbing of the economy. On the more immediate, "click-this-and-you're-done" side of things, we have TerminalFix. This is a variant of the ClickFix campaign that uses fake Cloudflare CAPTCHAs. You know the screen: "Verify you are human." Except instead of clicking a box with traffic lights, this one tricks you into executing a PowerShell command that deploys a reverse-tunnel backdoor. This is where the ten-person shop gets gutted. In a large corporation, there's a group policy preventing users from running arbitrary PowerShell scripts. In a small office, if a window pops up and says it's necessary to see a website, the employee will do whatever it asks just to get back to work. I've seen this pattern before with the "update your browser" pop-ups of five years ago. The mechanism changes—now it's a CAPTCHA—but the psychology is identical. It relies on the user's desire to remove a minor friction point as quickly as possible. The cost to mitigate this for an enterprise is a centralized management console and a SOC analyst who catches the weird outbound traffic. For you, the cost is zero dollars: it's a ten-minute conversation with your staff telling them that no legitimate website will ever ask them to copy and paste a command into a terminal to prove they aren't a robot. If you see a CAPTCHA that asks for more than a click or a puzzle, close the tab. We also have the usual ransomware noise. Rhysida is claiming a breach of a Berlin-based entity, demanding 30 BTC and threatening to leak nearly 6 terabytes of data. While the numbers are big, the story is old. The only new detail is the demand price. And then there's the regulatory hammer. GS Retail in South Korea was fined W12.8 billion won after a breach affecting 1.66 million users. It’s a staggering number that serves as a warning for anyone still hoarding data they don't need. If you're keeping customer records from 2019 "just in case," you aren't keeping an asset; you're maintaining a liability that could bankrupt you if the regulators decide to move into your neighborhood. The common thread this morning is the vulnerability of the "middle." Whether it's session tokens for AI, third-party vendor breaches, or fake CAPTCHAs, the attackers aren't looking for the front door. They're looking for the side entrance that was left propped open because it was too annoying to lock every time someone walked through. Check your browser extensions this week. If there is anything in there you didn't explicitly install and vet—especially "crypto-helpers" or "productivity boosters"—rip them out.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. Healthcare data breach exposes 3.75M patient records - Fox News Google News Security
  2. CareCloud Data Breach Affects 3.75 Million Americans - JFeed Google News Security
  3. CarGurus Data Breach Exposes 12.5 Million Accounts; Here's What Hackers Got - International Business Times, Singapore Edition Google News Security
  4. Manchester Airports Group breach exposes data of 8.7 million airport customers - Pasquale Pillitteri Google News Security
  5. Anthropic warns infostealer malware is hijacking Claude sessions to drain usage BleepingComputer
  6. GS Retail fined W12.8b over data breach affecting 1.66 million users - 헤럴드경제 Google News Security
  7. Chrome Web Store extensions caught stealing crypto, browser data BleepingComputer
  8. Rhysida Claims Berlin Hack: 5.79 TB, 30 BTC Demand [2026] - tech-insider.org Google News Security

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.