On 30 and 31 August, Anthropic revoked active Claude sessions and stripped saved payment methods from user accounts. The reason was not a breach of Anthropic. It was infostealer malware on customer machines, quietly lifting session cookies from browsers.
SecurityWeek, Help Net Security, Dark Reading and Security Affairs all place the same families at the scene. Vidar, LummaC2, StealC, RedLine and Acreed on Windows. Atomic Stealer on Mac. The mechanism is the boring part, and that is what makes it worth writing about. None of the passwords mattered. None of the second factors mattered. The cookie was the credential.
This is the identity story of the week, and it happens to be wearing an AI costume.
The cookie is the credential
A session cookie is a bearer token. Whoever holds it is treated as the authenticated user for the life of that session. Multi-factor authentication runs at login. Once the token is issued, MFA is behind you, not in front of you. An attacker who steals the cookie skips the whole ceremony.
Infostealers are built for exactly this. They sweep browser profiles, extract cookies, credentials and card data, and ship the lot to a marketplace within minutes. Anthropic's response, revoking sessions and clearing saved cards, is the correct move. It is also a tell. If the platform can only defend by mass-invalidating tokens after the fact, the perimeter has already moved to the endpoint.
For South African security leaders, the uncomfortable read is that this pattern is not new. What is new is where the tokens now live. They increasingly sit inside AI subscriptions that no one in the business has told the CISO about.
Shadow AI is a live identity problem
Most South African enterprises have not written down which AI services their staff are logged into on corporate laptops. Claude, ChatGPT, Copilot, Perplexity, Gemini and a long tail of wrappers. Some are paid on personal cards. Some are paid on company cards through expense claims. Some are federated to a Google or Microsoft identity that also unlocks the finance system.
That last category is where the Anthropic incident stops being about one vendor. If the infostealer took the Claude cookie, it almost certainly took every other cookie in that browser profile. The AI subscription is the visible loss. The identity blast radius is the actual loss.
This is a micro, meso and macro problem stacked in one incident. Micro, an endpoint executed a stealer because the user ran an installer they should not have run. Meso, the browser held federated identity tokens that reached into corporate systems the user did not consciously connect. Macro, an unmanaged category of AI SaaS spend has become a parallel identity fabric that sits outside the SSO estate the board thinks it is governing.
Procurement cannot solve what identity must
The instinct in most South African boardrooms will be to route this to procurement. Write an AI usage policy. Add Claude and ChatGPT to the approved list, or ban them, and move on. That instinct misreads the incident.
Procurement controls what the company buys. It does not control what a browser has already remembered. The Anthropic sessions were drained because a laptop had a cookie, not because a finance approver had signed a contract. A policy that lives in a PDF does not touch the token cache.
The work sits with the identity and endpoint teams, and it is closer to identity threat detection than to vendor management. That means treating browser session state as a monitored asset. It means endpoint detection tuned to the specific stealer families named in the reporting, not generic AV signatures. It means shortening session lifetimes on any AI service that supports it, and forcing reauthentication on sensitive actions inside federated apps. It means an inventory of which AI subscriptions are logged in on which managed devices, built from telemetry rather than from a survey.
None of that is glamorous. All of it is cheaper than the first serious cross-contamination event, where the stolen Claude cookie turns out to have been sitting next to a Microsoft 365 cookie that opened the mailbox of a finance director.
The operational stance
Detection is not protection. Containment is. Anthropic contained by invalidating sessions at the platform. South African CISOs cannot rely on every AI vendor doing the same on the same day.
The operational mandate is narrow and specific. Treat every AI SaaS session on a managed device as a federated identity asset. Audit device browser state monthly. Shorten token lifetimes where the vendor allows it. Wire the named stealer families into endpoint detection this week, not this quarter. And put shadow AI subscriptions on the same risk register as any other unmanaged identity provider, because that is what they have quietly become.

