Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

Stolen Claude Session Cookies Bypass Corporate Gmail Protections and Evade IT Admin Revocation

Infostealer malware is being used to replay stolen Claude session cookies into paid accounts without triggering two-factor authentication or Single Sign-On (SSO) protections. These affected accounts are self-serve with direct card billing, outside the governance of corporate identity providers, making it impossible for IT admins to revoke sessions. Anthropic has responded by notifying users, signing out stolen sessions, removing saved payment methods, and refunding fraudulent charges. However, the sessions can potentially access Gmail inboxes, conversation histories, files, and connected services authorized by users — posing a significant security risk for corporate data. Attackers often obtain these cookies from infected devices, sometimes via pirated software or spoofed download sites. Experts recommend treating AI service sessions on compromised machines as breached, revoking any tenant permissions possible, and moving heavy users to managed organizational accounts with tighter controls like OAuth grant restrictions and device-bound session credentials. Endpoint security combined with identity governance and AI policy enforcement is critical to closing this security gap.

Venturebeat
Venturebeat