Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
VentureBeat1 newsroom
Picture: VentureBeat
Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards. The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly…