Anthropic locks Claude accounts after infostealers hijack login sessions

This digest was compiled by AI from multiple sources — links to the originals are below.
Anthropic has started locking users out of their Claude accounts after infostealer malware compromised login sessions. The move follows a week of disclosures including a 284 million patient record theft claim against McKesson and a CISA review urging elimination of vulnerability classes.
Key Facts
- Anthropic locked Claude users out after infostealer malware compromised their login sessions.
- ShinyHunters claimed it stole 284 million patient records from McKesson.
- August 2026 Patch Tuesday resolved 398 CVEs, the second highest monthly total in history.
- A CISA review argues for eliminating entire vulnerability classes rather than patching individual flaws.
- Russian state hackers planted a nuclear weapon prompt in malware to trip AI safety guardrails in Ukraine.
Claude Account Lockouts
Anthropic began locking users out of their Claude accounts after discovering that infostealer malware had hijacked login sessions. The company has not disclosed how many accounts were affected or when the compromise was first detected. Infostealers typically harvest session cookies and credentials from infected devices, allowing attackers to bypass multi-factor authentication.
McKesson Data Theft Claim
The ShinyHunters group claimed it stole 284 million patient records from healthcare company McKesson. McKesson disclosed a cybersecurity incident in which hackers accessed third-party applications and stole data. The company has not confirmed the number of affected individuals or the nature of the stolen data.
Patch Tuesday Forecast
August 2026 Patch Tuesday resolved 398 CVEs, including 42 rated Critical and 355 rated Important. The September 2026 Patch Tuesday forecast indicates that the record pace of vulnerability disclosures will continue. A CISA review argues that eliminating entire vulnerability classes at the source is more effective than patching individual flaws.