Original Reddit post

I was recently the victim of a phishing attack that appears to have compromised credentials or active sessions associated with my Claude account. Since discovering it, I have taken every security measure available to me: Changed the passwords for Claude’s associated login and email account. Logged out of all active Claude sessions repeatedly. Revoked connected sessions and authorization tokens visible in the account. Removed stored Claude Code sessions. Disabled and removed Claude browser integrations. Uninstalled Claude Desktop and stopped all identifiable Claude-related services and processes. Removed local Claude Code installations, configurations, cached sessions and automation. Disabled additional paid usage and automatic credit reloads. Audited the affected systems for background processes and persistence. Despite all of this, the account’s usage continued increasing until the available allowance was completely exhausted, even while I was not using Claude and no identifiable Claude client was running locally. I understand that usage reporting can sometimes be delayed, and I am not claiming to know the technical cause. However, the continued increase after repeated global logout, password rotation and removal of all visible clients is extremely concerning. From a user’s perspective, the available account-security controls did not stop the unauthorized activity. The most difficult part is that I cannot safely access support without logging back into the affected account. I contacted the automated support assistant and was told that the case would be passed to a human, but I have received no response. There does not appear to be an accessible emergency channel for freezing a compromised consumer account or forcing server-side revocation of every session and token. I am not publishing technical indicators, account information, infrastructure details or evidence because I do not want to expose sensitive information or interfere with an investigation. What I need from Anthropic is straightforward: Temporarily freeze the account. Revoke every server-side web, Desktop, Code, Cowork, OAuth and bearer session or token. Preserve and review the authentication and usage logs. Identify which session or Claude surface generated the activity. Provide a secure way to recover the account and review unauthorized usage. Has anyone experienced something similar or found a reliable way to reach Anthropic’s account-security or human support team without continuing to log into the compromised account? submitted by /u/EvenGeologist1973

Originally posted by u/EvenGeologist1973 on r/ClaudeCode