Stolen Claude Cookies Bypass 2FA and Put Corporate Gmail at Risk
Anthropic invalidated Claude sessions stolen by six infostealers, exposing self-serve AI accounts and potentially corporate Gmail and Drive data access.
Summary
Anthropic invalidated stolen Claude sessions after Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on some Macs, copied browser cookies and replayed them past 2FA and SSO. Usage limits refilled and drained while owners were absent. Anthropic signed affected users out, removed saved cards and refunded detected charges, but disclosed no victim count or whether Team or Enterprise seats, chats, files or connectors were accessed. Card billing indicates self-serve accounts, including personal subscriptions, although Team and self-serve Enterprise organizations may also qualify.
A replayed cookie inherits the user’s access. Claude connectors can read and search without approval, while writes such as sending, forwarding, sharing, moving or trashing require approval by default. Personal Google Workspace connections can therefore expose corporate Gmail or Drive through employee-owned grants invisible to Claude tenant administrators, although Workspace or Entra administrators can revoke the underlying consent. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations use personal identities, rising to 61% for Claude. One victim linked infection to a pirated game; separate FakeAgent lures used a claude.ai Artifact and sponsored Bing ad, compromising employees at 29 organizations in two days and drawing about 7,100 downloads.
CrowdStrike says stolen ChatGPT, Claude and Gemini credentials have traded since late 2022; its 2026 Threat Hunting Report logged nearly 200,000 API requests in two minutes from one compromised cloud account. Okta made Agent SSO generally available August 24, yet July research found 63% of 116 enterprises share some agent credentials and only 3% use Okta for AI Agents. Defenders should clean endpoints, revoke Claude sessions and Google or Microsoft OAuth grants, restrict personal app consent, and move heavy users to managed tenants. Google introduced Device Bound Session Credentials in Chrome 146 on Windows in April and enabled them by default for Google and Workspace Individual accounts in May; Macs remain uncovered.
Positives
- Anthropic invalidated stolen sessions, removed saved payment methods and refunded the unauthorized charges it detected.
- Common Room launched its first agent integration in October 2025 with Auth0, separate read and write scopes, and writes disabled by default.
- Okta made Agent SSO generally available August 24, giving AI agents governed identities and short-lived tokens through Universal Directory.
- Chrome 146 introduced Device Bound Session Credentials on Windows, preventing copied Google session cookies from being refreshed on another device.
- Google Workspace and Microsoft 365 administrators can restrict third-party authorization and revoke OAuth grants already issued to Claude.
Risks & concerns
- Anthropic disclosed no victim count or confirmation about access to Claude conversations, project files, connectors, Team accounts or Enterprise seats.
- LayerX found personal identities handle 47% of enterprise AI conversations overall and 61% of Claude conversations.
- FakeAgent compromised employees at 29 organizations in two days and attracted roughly 7,100 downloads through a malicious claude.ai Artifact.
- CrowdStrike documented nearly 200,000 AI API requests made in two minutes through one compromised cloud account.
- July research found 63% of 116 enterprises share credentials among AI agents, while only 3% use Okta for AI Agents.
- Copycat phishing emails now impersonate Anthropic’s breach notifications, creating another route to compromise affected users.