Two-factor authentication is still one of the best ways to protect an online account, but it cannot stop every kind of account takeover. A growing threat targets something different: the browser session created after you successfully sign in. Recent Claude account thefts show how infostealer malware can steal authenticated sessions, giving criminals access without repeating the password and two-factor authentication process users expect to stand between them and an attacker.
When Session Theft Skips Login
A recent incident involving Anthropic’s Claude AI service shows what this kind of attack can look like in the real world. Anthropic warned affected users that general-purpose infostealer malware already running on their computers had stolen active Claude login sessions. Attackers then used those sessions to access accounts and consume the users’ Claude usage. The important detail is where the attack began. It was not a breach of Claude’s login system. The malware was already on the user’s computer.
Anthropic reportedly responded by signing affected users out, removing saved payment methods, and refunding charges it identified as unauthorized. The company also said it had no reason to believe the malware came from Claude or was installed through Claude. Instead, the affected machines were likely infected through malicious applications, unofficial downloads, or similar sources before the Claude sessions were stolen.
According to BleepingComputer’s reporting on the Claude session thefts, the malware collected login sessions along with other locally stored information. One affected user said a pirated game had been downloaded before the compromise, offering a likely explanation for how the malware reached that computer.
This is what makes the story bigger than Claude. If a criminal obtains a valid authenticated session, the target website may receive something that effectively says the user has already logged in. Instead of beginning with a stolen password and fighting through the normal security checks, the attacker may try to reuse trust that has already been granted.
What Your Browser Session Does
Signing into a website feels simple, but quite a bit happens in the background. You enter a password, use a passkey, or provide another credential. The service may also ask for an authenticator code, security key, push approval, biometric check, or some other second factor. Once those checks succeed, though, the website usually does not ask you to repeat them every time you click another page.
Imagine having to enter a password and six-digit code each time you opened another email, viewed another cloud file, or moved around an online banking site. It would become frustrating almost immediately. Websites avoid that problem by creating a session that lets your browser stay recognized after the initial login.
Depending on the service, that session may rely on cookies, access tokens, refresh tokens, or other authentication data. Your browser presents the needed information as you continue using the site, and the service can recognize that authentication already took place.
Microsoft’s explanation of authentication tokens and token theft describes several token types with different purposes and lifetimes. Microsoft also notes that once a token is stolen, an attacker may be able to impersonate the user and gain unauthorized access.
A simple way to look at it is this: your password helps prove who you are during login. A valid session helps prove that you already completed the login. That difference may sound small, but from an attacker’s point of view, it can be enormously valuable.
Why 2FA May Not Stop It
Two-factor authentication, or 2FA, still provides strong protection. If a criminal steals your password through phishing, malware, a data breach, or password reuse and then attempts a fresh login, 2FA puts another barrier in the way. Knowing the password alone may not be enough to enter the account.
Session theft targets a later stage. Suppose malware on your computer steals a usable authentication token after you have already entered your password and completed 2FA. Depending on the service, the token involved, whether it remains valid, and the security controls in place, an attacker who reuses that token may not be asked to complete a fresh password or 2FA challenge.
Microsoft warns in its identity security recommendations that attackers can extract authentication tokens from local storage or memory and attempt to replay them. Microsoft also recommends token protection for supported environments because binding a token to its original device can make stolen tokens unusable from an attacker’s machine.
That distinction is important because it is easy to hear “2FA bypass” and assume 2FA no longer works. That is not what is happening. Two-factor authentication still blocks many common account takeover attempts and should remain enabled wherever possible.
The issue is that 2FA mainly protects the authentication process. Infostealer malware may go after the authenticated session that exists once that process is already finished.
How Infostealers Reach Browsers
Infostealers are designed to quietly collect valuable information from infected computers and send it back to criminals. Unlike ransomware, which often makes itself obvious by encrypting files or disrupting a system, an information stealer benefits from staying unnoticed. The longer nobody realizes it is there, the more information it may have time to collect.
In the Claude incidents, Anthropic reportedly identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows systems. Atomic Stealer, also known as AMOS, appeared on a smaller number of Macs. These are not Claude-specific threats. They are broader malware families that can hunt through browsers and applications for information worth stealing.
Microsoft’s analysis of Lumma Stealer and its capabilities found that Lumma can extract saved passwords, session cookies, and autofill information from multiple browsers. It can also search for cryptocurrency wallet data, application credentials, documents, and other useful information.
Now think about what may already be available through the browser on an ordinary home or work computer. Email, cloud storage, shopping accounts, social media, AI services, accounting software, payment portals, website administration, customer systems, and business dashboards may all be signed in at the same time.
That concentration of access is what makes an infostealer dangerous. A criminal may compromise one computer but collect information tied to several unrelated services. The browser can become a doorway into a much larger piece of the victim’s online life.
Password Changes Are Not Enough
Changing your password after suspicious activity is still a smart response. The mistake is assuming that everything is fixed as soon as the new password is saved. If session theft or infostealer malware may be involved, account recovery needs to go further.
Passwords and active sessions are related, but they are not the same thing. The password generally helps establish access. A session or authentication token can help maintain that access afterward. Because of that, changing the password does not necessarily mean every existing session disappears at the exact same moment.
What happens depends on the service. Some platforms automatically invalidate certain sessions or tokens after a password change. Others provide separate controls for ending sessions, removing devices, or revoking connected access. That is why security pages may offer options such as:
- Sign out of all devices.
- End active sessions.
- Remove unfamiliar devices.
- Revoke connected applications.
- Revoke tokens or account access.
Google, for example, lets users review devices and active account sessions and sign out of sessions they do not recognize. Google also explains that one account can have several sessions because different browsers, devices, apps, and services may each create their own.
After suspected session theft, changing the password and reviewing active sessions belong in the same recovery process. The password change helps protect future authentication. Revoking suspicious sessions can help shut down access that may already exist.
One PC Can Expose Many Accounts
Finding suspicious activity on one account does not necessarily mean only that account was touched. That is an easy assumption to make, especially when one service is the first place where something obviously goes wrong. Infostealers, however, are generally built to collect whatever valuable information they can reach.
A stolen Claude session might simply be the first item that causes noticeable trouble. The same infection may also have been able to access browser passwords, cookies, authentication tokens, autofill information, local files, cloud credentials, application credentials, or other data stored on the computer.
Microsoft has documented how newer infostealers are expanding across Windows and macOS, with recent campaigns harvesting browser credentials, saved passwords, session data, cloud credentials, cryptocurrency information, and other secrets.
Email deserves special attention after an infection like this. For many people, their primary email account sits at the center of almost everything else they use online. Password resets arrive there. Security warnings arrive there. Billing records, account verification messages, receipts, and recovery links often end up in the same inbox.
If a criminal gains control of that email account, the problem can spread far beyond whichever service first showed signs of abuse. What started as one infected computer can turn into a much larger account recovery problem.
So after a confirmed infostealer infection, the better question is not simply, “Which account was hacked?” It is, “What accounts, sessions, passwords, files, and applications could this computer access while the malware was running?”
Why Small Businesses Should Care
Session theft can be especially damaging for a small business because so much daily work happens through a browser. One employee computer might already be signed into Microsoft 365 or Google Workspace, payroll, accounting software, cloud storage, a CRM, website administration, social media accounts, vendor systems, AI tools, and payment services.
Using separate passwords and MFA across those accounts is still good security practice. The weakness is that many of those services may share another point of exposure: the computer holding their active sessions. If that endpoint becomes infected, the attacker may not need to attack each online service from the beginning.
The Federal Trade Commission’s cybersecurity resources for small businesses recommend measures such as keeping software and browsers updated, using multifactor authentication, limiting access to sensitive information, using security software, training employees, and having an incident response plan.
For businesses concerned about session theft and infostealers, several steps deserve extra attention:
- Keep operating systems, browsers, applications, and security software updated.
- Limit administrator privileges to employees who genuinely need them.
- Use centrally managed endpoint protection where practical.
- Restrict pirated software, unofficial downloads, and unapproved applications.
- Review active sessions and account activity whenever malware is found.
- Prioritize email, administrator, financial, and cloud accounts during recovery.
This is where endpoint security and account security overlap. A business can use excellent passwords, strong MFA, and carefully controlled user accounts, but the computer holding those authenticated sessions still needs protection of its own.
What To Do After Suspected Theft
If you discover an infostealer infection, unexplained account activity, or evidence that a browser session may have been stolen, the order of your response matters. One of the easiest mistakes is signing back into every important account from the same computer before confirming that the malware has actually been removed.
Anthropic warned affected Claude users that signing them out invalidated the stolen Claude sessions, but it did not remove the malware from their computers. If the infostealer remained active, the next login session could potentially be stolen again.
Start with the device. Avoid using the suspected computer for sensitive logins until it has been investigated and cleaned. Depending on the severity of the infection and what the system had access to, that could mean using trusted security software, seeking professional help, or performing a clean operating system reset or rebuild.
Then move account recovery to a device you trust:
- Secure your primary email account and review its recovery information.
- Sign out unfamiliar devices and revoke suspicious sessions or access.
- Change important passwords from the trusted device.
- Review 2FA methods and remove anything you did not add.
- Check recent sign-ins, purchases, billing activity, and security alerts.
- Review credentials that were saved or regularly used on the infected computer.
Google’s recommendations for securing a compromised account include reviewing recent security events, checking devices with account access, changing compromised passwords, and correcting unfamiliar account settings.
Businesses should take the review a little further. Identify which company accounts were used from the infected endpoint and involve an IT provider or cybersecurity professional if the scope is unclear, administrator access was involved, or sensitive information may have been exposed. The account where you first notice something wrong may be only one part of the incident.
Frequently Asked Questions
Can stolen cookies bypass 2FA?
Yes, some stolen session cookies or authentication tokens can allow an attacker to reuse an already authenticated session without completing a fresh 2FA challenge. Whether it works depends on the service, the type of session data stolen, whether the session is still valid, and what additional protections the provider uses.
Does changing my password end sessions?
Not always. Some services invalidate existing sessions or tokens when the password changes, while others provide separate controls for signing out devices or revoking access, so it is worth checking the account’s security settings after a suspected compromise.
Is 2FA still worth using?
Yes. Two-factor authentication remains one of the strongest ways to reduce account takeovers caused by stolen or reused passwords, even though it cannot prevent every attack involving an authenticated session that was stolen afterward.
Can Macs get infostealer malware too?
Yes. Infostealers increasingly target macOS as well as Windows, and Anthropic reportedly identified Atomic Stealer on a smaller number of Macs connected to the Claude session theft incidents.
Should I log in again after a scan?
Only after you have reasonable confidence that the computer is clean. If the infostealer is still running, signing in again could create fresh session information for the malware to collect.
Protect More Than the Login Screen
The Claude incident does not mean passwords, passkeys, or 2FA are failing. They still matter, and people should keep using them. What the incident exposes is another part of account security that most users rarely have a reason to think about: the trust that remains on a computer after the login screen is gone.
Once you sign in, your browser may hold cookies, tokens, and other information that keep accounts open and make the web easier to use. That convenience is useful to you, but it can also be useful to an attacker. Malware that reaches the endpoint may target the browser’s existing authenticated session instead of trying to work through the password and 2FA process from scratch.
For home users, the response is practical. Keep 2FA enabled. Use unique passwords or passkeys where available. Avoid pirated software and questionable downloads. Keep the operating system, browser, and security tools updated. If infostealer malware is discovered, treat it as more than a password problem. Clean the device, revoke active sessions, review your important accounts, and only then resume sensitive logins from a computer you trust.
Small businesses need the same approach on a wider scale. Strong authentication, endpoint protection, software controls, employee awareness, session management, and incident response reinforce one another. JENI® Systems encourages a layered approach to everyday computer security because protecting an online account also means protecting the computer where that account is already signed in.
Cybercriminals still want passwords, and that is unlikely to change. But the password is no longer the only useful proof of identity sitting on a computer. Sometimes the more valuable target is the browser session showing that the real user already passed the security checks.
Related Articles
Browser Security: Passwords, Cookies & Extensions
Learn how browser passwords, cookies, extensions, and stored data can expose accounts, plus practical steps to strengthen everyday browser security.
Account Takeover and Malware Risks
Learn how malware and stolen credentials can lead to account takeover, which warning signs matter, and what you can do to protect your online accounts.
Account Recovery Security Settings
See how recovery emails, trusted devices, backup codes, and outdated account settings can create security gaps, plus which settings you should review.
Token Theft and Faster Cyberattacks
Learn how stolen authentication tokens and automated attacks can give criminals faster access to online services and change the way accounts are targeted.
