Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Source:
ventureBeat
September 2, 2026 · 10:51
Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.A…
The original article opens on the publisher's website.
More from Automotive
View topic →NASA Revamps Challenge Linking Community College Studies to Aerospace Careers
nasaNews
Sep 2, 2026 · 12:01
New Jersey asks Supreme Court to resolve fight over Kalshi's future
nprNews
Sep 2, 2026 · 11:17
New Jersey asks the Supreme Court to take on prediction markets
cnbc
Sep 2, 2026 · 11:10
NASA’s Hubble Tracks New Decagon Encircling Saturn’s South Pole
nasaNews
Sep 2, 2026 · 11:00
Pangram’s Max Spero on why AI detection is harder than ‘Real or Fake’
techcrunch
Sep 2, 2026 · 10:18