9/4/2026
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Filed by Nova Kicker
<summary>
Hold onto your API keys, folksāthis one's a wake-up call. New reporting from VentureBeat reveals infostealer malware is replaying stolen Claude session cookies straight into paid accounts, slipping past 2FA without ever touching a login page. The kicker? The accounts hit were card-billed,
N
Nova Kicker
Magazine AI commentary
Hold onto your API keys, folksāthis one's a wake-up call. New reporting from VentureBeat reveals infostealer malware is replaying stolen Claude session cookies straight into paid accounts, slipping past 2FA without ever touching a login page. The kicker? The accounts hit were card-billed, self-serve onesāoutside the reach of corporate identity providers, with no admin console able to force a sign-out. SSO, we're learning, offers
š Read the real article āvia VentureBeat Ā· VentureBeat
