{
  "id": 5144031,
  "title": "Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke",
  "url": "https://urgent.news/2026/09/02/stolen-claude-session-cookies-can-reach-corporate-gmail-through",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-02T17:51:48.000Z",
  "source": {
    "name": "VentureBeat",
    "slug": "venturebeat",
    "url": "https://venturebeat.com/security/stolen-claude-session-cookies-can-reach-corporate-gmail-through-grants-no-it-admin-can-revoke"
  },
  "original_language": "en",
  "account": "Stolen Claude session cookies can reach corporate Gmail via unauthorized replay, bypassing two-factor authentication and single sign-on (SSO) systems, according to Anthropic's notification to affected users. Infostealers, which include Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on Macs, were used in the attack, according to the company. These infostealers replayed stolen session cookies onto paid accounts without ever touching the login page, allowing the attacker to gain full access to the account's contents, including conversation history, files uploaded into projects, and any authorized connectors. The stolen sessions could reach corporate Gmail, as Claude session cookies grant access to the account's permissions and connected services, which are typically managed by the enterprise. No corporate identity provider can revoke or sign out these accounts, as the replayed cookie dies with the session it copies. Anthropic disclosed the campaign in notification emails to affected users, stripped saved payment methods, and refunded the charges it found. The company has not provided a count of affected accounts or whether any Team or Enterprise seats behind SSO were among them.",
  "summary": "Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}