Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

Image: Dark Reading
ad slot · in-content video 16:9
Coverage
Coverage
- A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
More coverage
- Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console…