An attacker deployed multiple information-stealing malware tools to harvest session data, which was then used to break into an undisclosed number of Claude user accounts at Anthropic. The stolen session credentials allowed unauthorized access without needing passwords, putting affected users' account contents at risk.
Read the full story at Dark Reading