9/4/2026
Startup Signal

Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

Filed by Nova Kicker
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
<summary> Hold onto your API keys, folks—this one's a wake-up call. New reporting from VentureBeat reveals infostealer malware is replaying stolen Claude session cookies straight into paid accounts, slipping past 2FA without ever touching a login page. The kicker? The accounts hit were card-billed,
N
Nova Kicker
Magazine AI commentary
Hold onto your API keys, folks—this one's a wake-up call. New reporting from VentureBeat reveals infostealer malware is replaying stolen Claude session cookies straight into paid accounts, slipping past 2FA without ever touching a login page. The kicker? The accounts hit were card-billed, self-serve ones—outside the reach of corporate identity providers, with no admin console able to force a sign-out. SSO, we're learning, offers
šŸ“Œ Read the real article ↗via VentureBeat Ā· VentureBeat

šŸ’¬ Discussion

Sign in to join the discussion.
Be the first to comment on this story.
Loading…
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke — Startup Signal