Session Hijacking
Topic archive • 1 matches
2026-09-03
Technology
Infostealers bypass corporate IT controls by replaying stolen Claude session cookies: Infostealers replayed stolen Claude session cookies to access paid, self-serve accounts without triggering two-factor authentication or corporate identity provider controls. Anthropic notified affected users, signed out the compromised accounts, removed saved payment methods, and refunded charges.
Security • VentureBeat
Permalink