Hackers targeting artificial intelligence subscriptions are consuming Anthropic’s Claude users’ token quotas without authorization. In the UK, consultant Grant De Swardt noticed that usage on his Claude Max 20x account, for which he pays $200 per month, had risen from 45% to 55% on days when he had not used the service. Anthropic suspended the account and invalidated the sessions and server-side tokens, and issued a partial refund for the remaining period; however, the consultant’s work was disrupted. An investigation found that the compromised Claude session key had been used to generate unauthorized OAuth tokens and carry out third-party operations. Other users reported unauthorized plan upgrades, card charges and quotas being rapidly depleted. The company said that sessions stolen by infostealer malware had been used, and that the infection originated not from the service but from infected software and advertisements.
Why it matters
The incident shows that the compromise of artificial intelligence accounts can affect not only personal data but also paid usage rights and the account’s access to business processes. In particular, users of high-quota subscriptions may face both unexpected expenses and service disruptions if their session information is stolen through malware and advertisements. Although Anthropic’s invalidation of server-side tokens and partial refund were intended to mitigate the damage, suspending the account can disrupt users’ ongoing work. The open question is under what conditions compromised sessions can be detected and how the scope of unauthorized use will be determined; the company’s statement indicates that the infection originated not from the service but from infected software and advertisements.
Background
Claude is not a new name in the FikirPilot archive: we have published 7 articles mentioning it in the past 90 days, the latest dated 10 September 2026.