Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
2026-09-03 01:51General🔥 36.0 heat score
1sources
1days unfolding
36.0heat score
3mentions
SummaryAI generated
After hackers obtain Claude session cookies, they may access corporate Gmail accounts through an authorization mechanism. Such access is not limited by IT administrators’ permission revocation, posing a security vulnerability.
Infostealers replayed stolen Claude session cookies to burn usage on paid self-serve accounts without bypassing login pages or two-factor authentication. The attack targeted card-billed accounts not governed by corporate identity providers, allowing attackers to reach resources beyond enterprise control. Anthropic disclosed the campaign via notification ema…