Caution with Claude: How hackers are targeting Anthropic’s popular AI platform

What happened?

Anthropic, recently began warning its users about how its platform, Claude, is being targeted by cybercriminals seeking to steal their users’ sensitive information. Earlier this month, Anthropic contacted some of its Claude users warning them that cybercriminals are now using information stealing malware to take over their accounts. This new trend presents a risk to the data contained in the Claude user’s account.

Key takeaways:
  • In the past couple of weeks, Anthropic sent emails to some Claude users warning them that cybercriminals had installed infostealer malware to copy user login sessions, saved passwords, login cookies in browsers, and locally stored credentials.
  • By copying the user’s authenticated login session, the cybercriminals are able to bypass entering the user’s standard credentials and multifactor authentication.
  • While Anthropic states that it has no reason to believe the malware was related to Claude, installed through Claude, or related to anything the user did with Claude, it is clear that cybercriminals are targeting Claude users with infostealer malware.
Analysis:

While it is suspected that cybercriminals are likely using this malware in order to use the Claude account’s paid capacity for free, with access to the user’s Claude account, they will also have access to the data contained therein. So, to the extent any sensitive data has been ingested into Claude, there is the possibly that this sensitive data could also be compromised. If that is the case, the cybercriminal could then leverage it for malicious purposes such as ransom, fraud, social engineering, or to enable other subsequent attacks.

Conclusion:

Cybercriminals are now targeting Claude user accounts in hopes of hijacking their authenticated login sessions to copy passwords, login cookies and other credentials. If an account is compromised, the data contained therein is also potentially compromised and could be leveraged by the cybercriminal to further their nefarious activities.

If you have questions, contact a member of McDonald Hopkins' Data Privacy and Cybersecurity Practice Group.

Jump to Page

McDonald Hopkins uses cookies on our website to enhance user experience and analyze website traffic. Third parties may also use cookies in connection with our website for social media, advertising and analytics and other purposes. By continuing to browse our website, you agree to our use of cookies as detailed in our updated Privacy Policy and our Terms of Use.