{
  "id": 5136607,
  "title": "Infostealers replayed Claude session cookies straight past 2FA. The accounts the evidence points to are personal subscriptions outside your SSO",
  "url": "https://urgent.news/2026/09/02/infostealers-replayed-claude-session-cookies-straight-past-2fa-the",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-02T17:51:48.000Z",
  "source": {
    "name": "VentureBeat",
    "slug": "venturebeat",
    "url": "https://venturebeat.com/security/infostealers-replayed-claude-session-cookies-straight-past-2fa-the-accounts-the-evidence-points-to-are-personal-subscriptions-outside-your-sso"
  },
  "original_language": "en",
  "account": "Infostealers have been able to replay stolen Claude session cookies into paid accounts, bypassing two-factor authentication (2FA) and single sign-on (SSO) safeguards. Anthropic, the company behind Claude, notified affected users about the campaign, naming six families of malware used by the attackers: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on Macs. The stolen session cookies, which act as proof of a login, were used to replay the user's account without touching the login page. This session theft is likened to the new credential theft by Help Net Security. While SSO provides revocation and visibility, it does not prevent the attack. The accounts affected were primarily personal, self-serve subscriptions, which are not governed by corporate identity providers or admin consoles. The company refunded the charges for the burned usage and revoked the accounts to prevent further misuse. However, the replayed sessions could potentially reach sensitive information such as conversation history, uploaded files, and authorized connectors, posing a significant risk.",
  "summary": "Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides…",
  "key_points": [
    "Infostealers replayed Claude session cookies past 2FA",
    "Six malware families used by attackers: Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer",
    "Affected accounts were personal subscriptions, not corporate"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}