FlashFeed
๐Ÿ’ป
Stolen Claude session cookies gave attackers access to corporate Gmail accounts
๐Ÿ’ป Technology

Stolen Claude session cookies gave attackers access to corporate Gmail accounts

Attackers used six infostealer malware families to steal session cookies from paid Claude accounts, replaying them to gain access without ever triggering two-factor authentication. The hijacked sessions could reach corporate resources including Gmail, bypassing IT oversight entirely. Anthropic identified the campaign, signed affected users out, removed saved payment details and refunded fraudulent charges.

Comments

No comments yet