Skip to content

Session Hijacking

Topic archive1 matches

Back to homeGEO summary endpoint

2026-09-03

Technology

  • Infostealers bypass corporate IT controls by replaying stolen Claude session cookies: Infostealers replayed stolen Claude session cookies to access paid, self-serve accounts without triggering two-factor authentication or corporate identity provider controls. Anthropic notified affected users, signed out the compromised accounts, removed saved payment methods, and refunded charges.

    SecurityVentureBeat

    Permalink