Anthropic has started forcibly signing out Claude accounts and removing saved payment methods the moment it detects a device compromised by session-stealing malware. According to a notice one affected user shared publicly, Anthropic told the account holder it had found a bad actor using common infostealer malware to lift Claude login sessions directly from an infected computer, then use those sessions to run up usage on the victim’s account. For SEO and content teams that now route research, drafting, and client data through Claude and similar tools, the incident is a reminder that account risk no longer starts at the password.

The mechanism matters more than the headline. Infostealers do not guess passwords or brute-force logins. They copy the browser cookies and session tokens already sitting on an infected machine, then replay that session state to impersonate a logged-in user. Anthropic’s notice said the malware likely sat on the victim’s computer for some time before anyone touched Claude with it, quietly harvesting saved passwords and cookies from whatever apps ran locally.

That design choice defeats a control most teams treat as sufficient. One affected user said two-factor authentication did nothing to stop the takeover, because the attacker never needed a second factor. A stolen session token behaves exactly like a real, already-authenticated login. For agencies and in-house teams that share Claude seats across writers, strategists, and account managers, a single infected laptop can hand an outside party standing access to every conversation, prompt, and connected account tied to that session, not just one person’s credentials.

Anthropic said its response was limited to canceling the exposed sessions and removing the stored card, which forces a fresh login and a re-added payment method but does not clean the underlying infection. The company was explicit that the malware has no connection to Claude itself and typically arrives through unrelated downloads. Per Search Engine Journal, which reported the notice Sunday, the affected user later confirmed the source was a pirated file downloaded outside any Anthropic channel, consistent with how commodity infostealers usually spread.

The unresolved part is what happens after the sign-out. Anthropic’s message tells the user to log back in, not to assume the machine is clean. A security professional who reviewed the case in the same discussion thread argued that a full system wipe, not a password reset, is the only reliable fix, since this malware family tends to leave persistence mechanisms behind. Anthropic’s notice does not claim otherwise. It fixes the account-level exposure and leaves device-level remediation to the user.

For a marketing or SEO team, the practical takeaway is not to avoid AI tools but to treat the login the same way a shared CMS or ad-account credential is treated: assume any device running Claude, ChatGPT, or a similar assistant needs the same endpoint hygiene as a device with admin access to client accounts. Teams issuing shared or pooled AI logins should confirm what happens when a member’s session gets forcibly revoked, and should not treat a forced Claude sign-out as routine before ruling out a compromised endpoint.

Search Engine Journal reported the Anthropic infostealer notice on August 30, 2026.