Anthropic built an automatic tripwire for stolen AI logins, routed straight to your security team instead of theirs. That's the fix missing from this week's Claude hijacking scare
Anthropic's new Enterprise Frontier Safeguards adds automated detection for stolen or leaked AI credentials — the exact attack behind this week's Claude account hijackings — but only for enterprise customers, and only once they turn it on.
Anthropic's new Enterprise Frontier Safeguards, announced September 1, adds automated detection for stolen or leaked AI account credentials — the exact attack that let malware hijack Claude logins with no password and no two-factor prompt, a problem Anthropic disclosed the same week. For enterprise customers who turn it on, a flagged account routes straight to their own security team instead of into Anthropic's review queue. It's not available to the individual Claude logins most subs and small GCs are actually running today, and the rollout doesn't start until this fall.
What did Anthropic actually ship?
Enterprise Frontier Safeguards (EFS) bundles three opt-in controls for enterprise Claude customers: storing usage data on the customer's own cloud infrastructure instead of Anthropic's, encrypting it with customer-managed keys, and running automated scans across a rolling window of traffic for signals of serious misuse — attempted development of offensive cyber or biological capabilities, and stolen or leaked credentials among them. When something trips, the flag goes to the customer's own team; Anthropic says no employee review is required on its end. The company built it with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector, working with Amazon, Google, and Microsoft on the cloud side. Rollout starts in phases this fall, across Claude Enterprise, Claude Code, Amazon Bedrock, Google's Agent Platform, and Microsoft Foundry.
This is the delivery on a plan Anthropic previewed back on August 20 — letting enterprise customers self-host the data Anthropic is required to retain on its top-tier models. What's new here isn't the data-custody piece; it's the misuse-detection layer, and specifically who the flag reaches.
How does this connect to this week's Claude hijacking scare?
Days before EFS launched, Anthropic disclosed that commodity infostealer malware — already sitting on some users' machines from pirated software downloads — had been stealing active Claude login sessions and reusing them to drain accounts, no password or 2FA required. Anthropic's fix was reactive: sign the affected users out, wipe saved payment methods, refund the charges. That covers the billing damage. It doesn't tell you what an attacker saw in the meantime — chat history, uploaded spec sections, anything reachable through a connected Drive or SharePoint integration.
EFS's automated misuse scanning lists "signs of stolen or leaked credentials" as one of the exact patterns it watches for. For a firm on the enterprise tier with that control turned on, the same hijacking pattern gets caught continuously and reported to the firm's own security lead — not discovered days later from an Anthropic support email after the damage is done.
Who actually gets this, and when
| Tier | Who's on it today | What changes with EFS |
|---|---|---|
| Individual Claude Pro/Team login | Most subs and small GCs running AI for estimating, RFIs, or drafting right now | Nothing. Anthropic still catches hijacked sessions after the fact and refunds the bill; no automated flag goes to your team. |
| Claude Enterprise, Bedrock, Azure Foundry, or Google's Agent Platform with EFS opted in | Firms with an actual negotiated AI vendor agreement | Credential-theft patterns get flagged to your own IT or security lead as they happen; usage data can sit in your own cloud tenant under your own encryption keys. |
What still doesn't change
EFS doesn't fix the actual infection vector Anthropic named for the hijackings — pirated CAD, estimating, or takeoff software on the machine doing the logging in. It's opt-in even for customers who qualify, and "starting this fall" is Anthropic's own timeline, not a shipped feature yet. And it does nothing for the individual Claude or ChatGPT logins that most estimating and precon teams below the enterprise tier are actually using today.
The takeaway: if your firm has moved past individual seats into a real enterprise AI contract, this is the specific feature to ask your vendor rep about by name before your next renewal — confirm the misuse-detection flag reaches your security lead, not a vendor support queue you have to wait on. If you're still on individual logins, none of this applies yet; the session-hygiene basics from this week's hijacking story are still the whole defense.
This follows Anthropic's August 20 preview of self-hosted data retention — that piece covered who holds your data; this one covers who gets told when someone else is using your account to get at it.
Friday one chart. Every week, one piece of data that should change a decision on your project. Subscribe at constructionaibrief.com.
- What is Anthropic's Enterprise Frontier Safeguards (EFS)?
- EFS, announced September 1, 2026, lets enterprise Claude customers store their usage data on their own cloud infrastructure instead of Anthropic's, optionally encrypt it with their own keys, and turn on automated scanning that flags signs of serious misuse — including stolen or leaked credentials — directly to the customer's own security team rather than Anthropic's. It rolls out in phases starting this fall across Claude Enterprise, Claude Code, Amazon Bedrock, Google's Agent Platform, and Microsoft Foundry.
- Is this the same thing as the 30-day data retention change Anthropic previewed in August?
- It's the shipped, named version of that plan. On August 20, Anthropic told Bloomberg it would let enterprise customers self-host the data it's required to retain on its top-tier models. EFS delivers that data-custody piece, plus a new part that preview didn't include: automated detection of misuse signals, with the flag going to the customer instead of into Anthropic's own review queue.
- How does this connect to the Claude account hijacking Anthropic disclosed this week?
- The hijackings relied on commodity infostealer malware stealing an already-logged-in Claude session cookie, letting an attacker into the account with no password and no two-factor prompt. Anthropic caught it after the fact, signed victims out, and refunded charges. EFS's automated misuse detection explicitly watches for 'signs of stolen or leaked credentials' as one of its flag categories — the enterprise version of catching that same pattern before it runs up a bill, and routing the alert to the account owner's own team instead of waiting on Anthropic to notice.
- Does a sub running a handful of individual Claude logins get this protection?
- No. EFS is tied to an actual enterprise agreement — Claude Enterprise, Bedrock, Azure Foundry, or similar — not personal Pro or Team seats. Each control (customer-owned storage, customer-managed encryption keys, automated misuse review) is opt-in even for customers who qualify, and the rollout is phased starting this fall, not available today.
- What should a GC or sub actually do with this?
- If your firm already has, or is negotiating, an enterprise AI agreement, ask your admin or vendor rep whether EFS's automated misuse detection and customer-owned storage will be turned on when it reaches your account, and confirm the flag routes to your own IT or security lead. If your firm is still running on individual logins, this doesn't apply yet — the session-hygiene basics (no shared job-trailer logins, no AI accounts on machines running pirated CAD or takeoff software, periodic session review) are still the only defense.