News

Anthropic Warns Users of Active Campaign Stealing Claude Tokens

Anthropic has alerted Claude users to a security threat involving unauthorized token consumption on subscriber accounts. The warning comes after at least one user noticed their account was consuming tokens even when they weren't actively using the service.

While details about the attack vector remain limited, such campaigns typically involve phishing attempts, credential stuffing, or exploitation of session tokens to gain access to premium accounts. Hackers targeting AI platform subscriptions often aim to resell access or use the stolen compute resources for their own purposes.

Anthropic's warning to users underscores the importance of practicing good security hygiene when using AI services. Users are advised to monitor their account activity regularly, enable any available multi-factor authentication, and report suspicious behavior immediately. Given the increasing value of access to premium AI models, these accounts have become attractive targets for malicious actors.

The incident highlights a broader trend of cybercriminals targeting subscriptions across the technology industry, from streaming services to cloud platforms, as these accounts often contain valuable resources or personal data that can be exploited or resold.

Sources