Urgent.News

What's breaking now, across thousands of outlets.

Tech

Infostealers replayed Claude session cookies straight past 2FA. The accounts the evidence points to are personal subscriptions outside your SSO

Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides…

Infostealers replayed Claude session cookies straight past 2FA. The accounts the evidence points to are personal subscriptions outside your SSO

Infostealers have been able to replay stolen Claude session cookies into paid accounts, bypassing two-factor authentication (2FA) and single sign-on (SSO) safeguards. Anthropic, the company behind Claude, notified affected users about the campaign, naming six families of malware used by the attackers: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on Macs.

The stolen session cookies, which act as proof of a login, were used to replay the user's account without touching the login page. This session theft is likened to the new credential theft by Help Net Security. While SSO provides revocation and visibility, it does not prevent the attack. The accounts affected were primarily personal, self-serve subscriptions, which are not governed by corporate identity providers or admin consoles.

The company refunded the charges for the burned usage and revoked the accounts to prevent further misuse. However, the replayed sessions could potentially reach sensitive information such as conversation history, uploaded files, and authorized connectors, posing a significant risk.

Written by urgent.news from VentureBeat's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at venturebeat.com →

More in Tech

More from Wednesday 2 September →