Infostealer Malware Hijacks Anthropic Claude AI Sessions, Causing Financial Harm

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Infostealer malware has targeted Anthropic's Claude AI platform, hijacking active user sessions to bypass authentication and drain paid usage, resulting in unauthorized charges and privacy breaches. Anthropic is responding by revoking access, removing payment methods, and refunding affected users. The incident highlights vulnerabilities in AI session management exploited by malware.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (Claude) whose active sessions are hijacked by malware, leading to unauthorized use and financial loss for users. This constitutes harm to property through unauthorized charges. The AI system's use is directly linked to the harm, as the attackers exploit the AI system's session authentication to drain subscriptions. Therefore, this qualifies as an AI Incident due to realized harm caused by the AI system's compromised use.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital securityConsumer services

Affected stakeholders
Consumers

Harm types
Economic/PropertyHuman or fundamental rights

AI system task:
Interaction support/chatbotsContent generation


Articles about this incident or hazard