The internet is truly becoming a dangerous zone. Just for your information, below you can see an email I received yesterday. It came from <no-reply@email.claude.com>. It looked suspicious, and I tried to understand whether it was authentic. Some sources said that all legitimate emails coming from Anthropic arrive from the “anthropic.com” domain. But some recent data say that they started using the “claude.com” domain (h/t “Charles”).
The message said that my account was suspended, which wasn’t true, but it was true that someone had erased my payment method from their records. And the message contained a suspicious link that I didn’t dare to open. Besides, I noticed that someone had upgraded my Claude account from “pro” to “Max.”
I asked Claude, and he wasn’t sure himself whether this letter was real or a scam. I am now contacting Anthropic directly. For the time being, I am totally confused about what's happening. If someone knows more, please tell us in the comments.
The main point is that these things are becoming more and more sophisticated. Will there come a day when they’ll make the internet completely unusable for the average user?
_____________________________________________________________________
Hi,
We recently signed you out of Claude and removed the payment method saved on your account, so you’ll need to log back in and re-add your card. We’re sorry for the disruption. Here’s what happened and what we’ve done about it.
What happened
We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage. Our systems detected this activity on your account, and we’ve therefore removed your card on file and signed out the sessions involved to help block further unauthorized access.
If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.
How did this happen
Our investigation is ongoing. Our findings to date suggest that a computer you use with Claude is likely infected with infostealer malware, and may have been for some time. Phones and tablets do not appear to have been involved.
We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude. It’s general-purpose malware that typically arrives with an unofficial download or a malicious app, and it quietly copies saved passwords, login cookies in browsers, and credentials for other apps running locally. Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them.
The malware identified in this campaign so far include Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs.
What we’ve done
Signed out the sessions involved. Your Claude login session is saved on your computer, and the malware took a copy of it. Signing you out cancels that session everywhere, so the stolen copy stops working. This is why you had to log in again across your own devices. Please note that we might sign you out again if we see similar signs of account misuse.
Removed your saved payment method, so it can’t be charged through Claude. Your current plan continues for the billing period you’ve already paid for. To renew after that, or to make any purchase, you’ll need to add a payment method again in Settings.
Refunded Claude charges if we identified them as unauthorized. Refunds have already been applied so there’s nothing you need to do. If you see a Claude charge you don’t recognize that hasn’t been refunded, contact Support.
Recommended next steps
Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware. If it’s still on your computer, your next login session could be stolen the same way, so we recommend taking prompt action to remove the malware.
The below tips are general good practice for cleaning up after infostealer malware:
Scan computers you use with Claude for malware and remove any malware before any further computer use. See Apple’s guide to protecting against malware on Mac, and Microsoft’s guide to running a scan with Microsoft Defender on Windows.
After the malware has been completely removed, secure the email account you use for Claude by setting a new password, signing out of other devices, and enabling two-factor authentication.
Consider updating other passwords that were saved in any browser (e.g., banking, work, cloud services), and consider checking card statements if you store payment details in your browsers.
Only after you’ve completed the steps above, add a payment method again if you’d like your plan to keep renewing.
If you still see usage change while Claude is idle, or a charge you don’t recognize after completing these steps, reach out to usersafety@anthropic.com.
The Anthropic Team
Claude
Instagram LinkedIn X Youtube
Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104




Given the problems you've encountered with hijacks on your X account it could be that the email is genuine and there is malware on your computer that is possibly transmitting or has transmitted login details. Not sure if you use a windows or Mac but a very thorough sweep of your computer with antivirus software would be a good idea. I have heard good things about Bitdefender. And if you haven't already, bring in 2 factor authentication for your accounts. Of course, all this proves the point of your post - which is that the internet is becoming a warzone!
The recent increase in malware sophistication comes from AI itself:
The game has changed:” AI-powered malware scales up attacks
https://cybernews.com/ai-news/malware-ai-attacks/
AI-Powered Cyberattacks: How Artificial Intelligence Is Changing the Threat Landscape
https://www.techprescient.com/blogs/ai-powered-cyberattacks/
So it shouldn't be a surprise that standard "protection" gets evaded by modern malware.
Before the AI era that was possible with rootkits, mostly hiding in BIOS.
While the computer faculty of a university might have the tools to thoroughly search for such hidden malware and eliminate it, the average user can only set up a new system and change habits in a way that the usual means to steal info either become invalid or would expose an infiltrated system. Using an email client like Thunderbird instead of reading on the web, setting it to needing permission to show attachments is one of them, as often the malware arrives at attachment via an email address with a familiar name but on closer inspection, isn't.