โŒ

Reading view

Anthropic cracks down on hijacked user accounts mining AI tokens

Rather than paying for their own Claude usage, crims are using malware to steal access to other people's accounts. Aware of this issue, Anthropic has signed at least one affected user out and removed the saved payment method to stop stolen sessions being abused. According to an email shared by Reddit user WorriedAssociate7029, who sent a copy to The Register, Anthropic has been keeping an eye on a threat actor using infostealer malware to hijack Claude login details, session cookies, and other info needed to subvert multifactor authentication on user accounts. Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves. Fortunately for WorriedAssociate7029, Anthropic logged the user out of their account and deleted their stored payment method because it had detected evidence of attempted fraud. โ€œA few days ago, my social media accounts were hacked,โ€ WorriedAssociate said, adding that they'd managed to track the malware down with the help of Claude Opus 5 Max and, they believe, cleaned the system. โ€œBut last night I received this email from Anthropic warning me of an attempt to steal tokens via the API.โ€ They explained that the attempt failed, apparently thanks to Anthropic spotting it, but they realized that meant that the cybercriminal behind the incident seemed to have hijacked Google account credentials, cookies, and session IDs as well, since thatโ€™s how they were signed into Claude. After changing their password again and removing all active sessions, it appears they are now safe. Whoโ€™s eating your cookies? Anthropic made clear in the email that the credential theft wave itโ€™s identified has nothing to do with Claude itself, nor is it some sort of fancy, new-fangled, agentic AI malware thatโ€™s being used to create a base of accounts for bad actors to abuse. This is just good old-fashioned infostealer malware being turned to a new purpose, the email explains. โ€œWe have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,โ€ the email forwarded to us by WorriedAssociate and posted to Reddit stated. โ€œYour Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them.โ€ In this case, itโ€™s well-known infostealing malware too: Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer have all been fingered by Anthropic as being used to steal Claude credentials, sessions, and cookies. As for WorriedAssociate, they copped to making a noob mistake that led to their infection. โ€œI got fooled like a rookie by downloading a cracked game,โ€ they admitted in a comment on their post. โ€œNever again.โ€ As in their post, WorriedAssociate told us in a chat that they gave credit to Anthropic for cluing them in to the fact that they hadnโ€™t fully secured their accounts, and said they appreciated what the company did to help lock their Claude account down. โ€œThere have been several cases on Reddit in the past of accounts being hacked to steal tokens, and Anthropicโ€™s customer service seems pretty dreadful when it comes to refunds and account recovery,โ€ they told us. โ€œThis email appears to be new, and measures have finally been put in place to protect AI users.โ€ โ€œTokens are valuable and can be resold,โ€ WorriedAssociate added. So let this be a lesson: Providers might not catch every case of account theft, and AI accounts are the new hotness. Donโ€™t let your tokens be burned by someone else - theyโ€™re expensive and the last thing you want them to be used for is someone else's work. ยฎ

  •  

Turns out Brits would quite like their private messages to stay private

Brits have delivered a fairly unambiguous verdict on giving the government access to their encrypted messages: no, thanks. New polling commissioned by the Center for Democracy & Technology (CDT) found that 93 percent of British adults believe they have a right to private conversations online, while 89 percent think nobody should be able to access their personal messages without a court order. Perhaps more awkwardly for Westminster, two-thirds said they would not trust either the current government or any future one with the power to access encrypted messages. That distrust crosses political lines. Among people who voted in the 2024 general election, 58 percent of Labour voters said they wouldn't trust any government with the power, alongside 59 percent of Conservatives, 56 percent of Liberal Democrats, 69 percent of Greens and 75 percent of Reform voters. Public First did the asking, polling 2,000 British adults for CDT in April and weighting the results to reflect the wider population. The margin of error is 2.2 percentage points. The findings land as the UK government's appetite for slurping encrypted data continues to collide with the tech industry's insistence that encryption works best when nobody has a spare key lying around. That fight became particularly public when Apple withdrew Advanced Data Protection from UK users after receiving a secret Technical Capability Notice (TCN) under the Investigatory Powers Act. Apple challenged the order, and while the US government later said Britain had withdrawn its demand for access to Americans' encrypted data, reports have since suggested another TCN was issued focusing on British users. Despite the international row, 55 percent of those polled hadn't heard about the Apple notice at all. Once presented with the idea, enthusiasm remained thin. Just 12 percent backed the government being able to secretly order companies to provide access to users' information while preventing those companies from revealing the order. A third said the government shouldn't have that power at all, while another 41 percent wanted greater transparency or parliamentary oversight. Nor were respondents particularly sold on sacrificing security for law enforcement. 53 percent said the security risks of accessing encrypted messages outweighed the benefits, compared with 28 percent who thought the benefits came out on top. The reasons will sound familiar to anyone who has followed the encryption debate for more than five minutes. 84 percent worried that mechanisms allowing access to encrypted messages could introduce vulnerabilities for hackers and criminals, while 82 percent were concerned the powers could be abused. Knowing someone might be watching could also change how people behave. 65 percent said they'd become more cautious about what they liked, shared or commented on, while 41 percent said they'd self-censor criticism of public institutions or government officials. CDT is not a disinterested observer: the digital rights group campaigns for strong encryption and commissioned the research as part of that work. The polling itself, however, was carried out independently. Commenting on the research, Jim Killock, executive director of Open Rights Group, said: โ€œThe British public instinctively know that being able to communicate privately is crucial to our individuality and to the survival of a free and open society. โ€œThe government persists with the myth that it can weaken encryption to target the bad guys only. Attacks on the security of our phones, security tools and messaging apps harm us all and make our democracy weaker.โ€ None of this is likely to end Westminster's long-running pursuit of encrypted communications. But if ministers were hoping the public was enthusiastically behind them, the numbers suggest otherwise. ยฎ

  •  
โŒ