I noticed an email dated August 29 in one of my secondary Google accounts claiming that malware on my Mac or other Windows computers may be stealing my login sessions. I checked Activity Monitor for unfamiliar processes and didn't see anything suspicious. My M1 Mac is fully updated, and I understand that built-in protections such as XProtect run in the background. The message appeared to come from the Claude Team at [email protected] and included branding and a verified sender mark, so I'm unsure whether it's a legitimate account-security alert or a phishing attempt. How could the service know that my computer had malware, and what steps should I take to verify the warning and secure my accounts? Do I need a separate malware scanner?
3 Answers
For extra reassurance, you can run a reputable on-demand scanner such as Malwarebytes, but don’t install random antivirus tools recommended by the email. Keep macOS updated, review Login Items and browser extensions, and avoid running copied Terminal commands unless you understand them. If you didn’t click the message or install anything, the email alone is not evidence that your Mac is infected.
Claude wouldn’t normally be able to inspect your Mac and determine that it has malware just by sending an email. Treat the message as suspicious, especially if it urges you to click a link, install software, paste commands into Terminal, or provide credentials. Don’t use the links in the message; open Claude or your account provider by typing the official address yourself and check for security notifications there. Also inspect the full email headers rather than relying on the display name or logo, since those can be spoofed.
This may be a phishing message pretending to be an account alert. A verified mark or a clean-looking company template does not prove that the message is safe, and even a genuine sending address can sometimes be involved in a compromised mailing system. If you clicked anything, change the affected account password from the official site, enable two-factor authentication, review active sessions and connected applications, and revoke anything unfamiliar.

I trusted it because I had received other legitimate-looking Claude updates from the same address and the message included a verified mark. I’ll check my account directly instead of following the email and review my active sessions and connected apps.