๐Ÿ’ผFreshcollected in 9m

Stolen Claude Cookies Bypass 2FA and SSO

Stolen Claude Cookies Bypass 2FA and SSO
PostLinkedIn
๐Ÿ’ผRead original on VentureBeat
#session-cookies#infostealers#identity-security#access-controlclaudeanthropicclaudevidarlummac2atomic-stealer

๐Ÿ’กStolen Claude cookies can bypass 2FA and corporate SSO, exposing an overlooked AI-account governance gap.

โšก 30-Second TL;DR

What Changed

Stolen Claude session cookies let attackers access accounts without revisiting the login page or triggering 2FA.

Why It Matters

The incident highlights a governance gap for AI accounts created outside enterprise SSO: administrators may have no central visibility or revocation capability. Developers and companies should treat browser session theft as a separate risk from password or MFA compromise, especially when Claude can access sensitive conversations or connected services.

What To Do Next

Immediately sign out all Claude sessions, remove saved payment methods, and audit connected apps on any device suspected of running an infostealer before re-authenticating.

Who should care:Enterprise & Security Teams

Key Points

  • โ€ขStolen Claude session cookies let attackers access accounts without revisiting the login page or triggering 2FA.
  • โ€ขThe affected accounts were card-billed, self-serve accounts outside corporate identity-provider and admin-console control.
  • โ€ขAnthropic named Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer as malware involved in the campaign.
  • โ€ขAnthropic detected abuse through unusual usage-meter activity, then invalidated sessions, removed payment methods, and issued refunds.

๐Ÿง  Deep Insight

Background and context from public sources โ€” not the original article. 6 sources cited.

๐Ÿ”‘ Enhanced Key Takeaways

  • โ€ขThe attack vector relies on the persistence of session tokens stored in local browser databases, which remain valid until explicitly revoked or expired, regardless of the user's 2FA status.
  • โ€ขVictims remain vulnerable to repeated account takeover even after password resets if the underlying infostealer malware is not removed from the local host machine.
  • โ€ขThe campaign demonstrates a shift in cybercriminal focus toward 'AI-as-a-Service' platforms to exploit high-value compute credits and proprietary data access.
  • โ€ขThe use of Atomic Stealer confirms that the campaign successfully targeted macOS users in addition to the more common Windows-based infostealer targets.
  • โ€ขThe vulnerability highlights a critical gap in current web authentication standards where session cookies are not cryptographically bound to the specific hardware or browser fingerprint of the original session.
๐Ÿ“Š Competitor Analysisโ–ธ Show
FeatureAnthropic (Claude)OpenAI (ChatGPT)Google (Gemini)
Session SecurityCookie-based (vulnerable)Cookie-based (vulnerable)Cookie-based (vulnerable)
Enterprise SSOSupportedSupportedSupported
Malware TargetingHigh (Infostealers)High (Infostealers)High (Infostealers)
Billing ModelSelf-serve/EnterpriseSelf-serve/EnterpriseSelf-serve/Enterprise

๐Ÿ› ๏ธ Technical Deep Dive

  • Attackers utilize infostealer malware to scrape the browser's local storage and SQLite databases (e.g., Cookies, Web Data) where session identifiers are stored.
  • The exploit bypasses 2FA by replaying the 'session_id' or 'auth_token' cookie in the HTTP header of a new request, tricking the server into believing the request originates from an already authenticated session.
  • The attack operates at the application layer, rendering transport-layer security (TLS) and standard login-page 2FA ineffective because the authentication handshake has already been completed.
  • Malware families identified (Vidar, LummaC2, etc.) utilize C2 (Command and Control) infrastructure to exfiltrate stolen browser profiles, including saved credentials and session cookies, to remote servers.

๐Ÿ”ฎ Future ImplicationsAI analysis grounded in cited sources

AI platforms will mandate hardware-bound session tokens.
To mitigate cookie-replay attacks, platforms will likely move toward WebAuthn or device-bound session cookies that prevent tokens from being usable on unauthorized machines.
Increased adoption of short-lived session tokens.
Companies will reduce the TTL (Time-to-Live) of session cookies to minimize the window of opportunity for attackers who successfully exfiltrate browser data.

โณ Timeline

2023-03
Anthropic launches Claude 1.0, introducing self-serve paid subscription models.
2024-03
Anthropic releases Claude 3 family, significantly increasing the volume of enterprise and self-serve users.
2026-08
Anthropic detects anomalous usage patterns linked to session hijacking campaigns.
2026-09
Anthropic publicly acknowledges the cookie-replay campaign and initiates mass session invalidation.

๐Ÿ“Ž Sources (6)

Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.

  1. venturebeat.com
  2. youtube.com
  3. scworld.com
  4. gbhackers.com
  5. esecurityplanet.com
  6. reddit.com
๐Ÿ“ฐ

Weekly AI Recap

Read this week's curated digest of top AI events โ†’

๐Ÿ‘‰Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: VentureBeat โ†—

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.