Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA.
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
calendar_today
September 2, 2026
person
louiswcolumbus@gmail.com (Louis Columbus)
domain
venturebeat