Anthropic cracks down on hijacked user accounts mining AI tokens
AI summary · glm-5.3-flash
Commodity infostealer malware hijacked Anthropic user accounts, letting criminals mine AI tokens on victims' paid usage; Anthropic cracked down on affected accounts.
The Register reports that Anthropic is cracking down on user accounts hijacked through commodity malware that steals authenticated browser sessions. With the stolen sessions, thieves ran AI workloads to mine tokens, freeloading on victims' paid usage allowances. The campaign illustrates how infostealer operators now monetize AI platform credentials and sessions, not just financial accounts.
- Infostealers capture authenticated sessions, bypassing passwords
- Hijacked Anthropic accounts used to run token-mining workloads
- Anthropic took enforcement action against abused accounts
- Session theft extends to AI platform monetization
- Enforce MFA and session hygiene on AI services
VendorsAnthropic
ProductsAnthropic Claude
Malwarecommodity infostealer
VictimsAnthropic users
OrganizationsAnthropic
Full article
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
This source does not provide full text. Read it at theregister.com.