Anthropic is moving to lock down user accounts compromised by commodity malware that lifts authenticated sessions and quietly bills expensive model usage to the victim. The mechanic is small; the signal is large.

This marks the arrival of a new abuse category: metered-resource fraud aimed at AI. It rhymes with the cryptojacking wave of the last decade, but the target has shifted from CPU cycles to inference tokens. The economics are attractive to attackers precisely because AI usage is expensive, measured, and sold on the honor system of a valid session. Stealing a live session cookie also sidesteps multi-factor authentication entirely, which is why the info-stealer ecosystem has quietly become one of the most reliable initial-access channels in the market. For providers, the exposure is twofold. There is the direct fraud and chargeback cost, and there is the scarce-capacity problem: every stolen token consumes GPU time that paying customers cannot. Expect vendors to respond with shorter-lived tokens, device binding, per-account spend anomaly detection, and harder friction on new devices. That, in turn, reshapes what "good" enterprise AI governance looks like.

For Japanese enterprises, the timing is awkward. Many are only now standardizing on generative AI through corporate subscriptions and API keys, often without the session-hygiene controls that mature cloud programs assume. The historical pattern here favors perimeter defense over endpoint and identity posture, which is exactly the gap this threat exploits. Shadow AI compounds the problem: employees signing into personal or team plans on unmanaged laptops create the ideal target for a session-stealing payload.

For SIers and RPA vendors, this becomes a concrete service line rather than a talking point. The deliverable is no longer "connect the model" but "operate it safely": short-lived credential rotation, spend caps per project, usage-baseline monitoring, EDR coverage on any device that touches an AI console, and clear separation between build-time keys and human sessions. RPA bots that hold standing credentials deserve particular scrutiny, since an unattended automation account with billing power is a quiet liability.

The strategic read: AI cost is now an attack surface. Japanese IT leaders should treat token consumption like any other financial control, with budgets, alerts, and ownership, and assume that a stolen session, not a stolen password, is the more likely breach in the year ahead.