
A stolen AI account is now being resold on underground forums for a fraction of its official price. Anthropic just documented it in black and white: in its threat intelligence report published on September 10, 2026, the company describes a network that resold Claude access at up to 97% below the normal price, while quietly spying on users who thought they had found a good deal. For an SME subscribed to Claude, ChatGPT or Gemini, or tempted by a discounted AI access offer, this report arrives at the right time.
At a glance
- Anthropic published a report on September 10, 2026 covering malicious activity detected between December 2025 and August 2026.
- A network nicknamed "Poison Claude" resold access to Claude Opus and Sonnet at 5-15% of the official price, routing traffic through an intermediary server able to read every prompt and every response.
- According to the Google Threat Intelligence Group (GTIG), black market prices for stolen AI accounts (Claude, Gemini, Cursor Pro, Devin) more than doubled during 2026, a sign of rising demand.
- A batch of stolen data analyzed by Okta contained valid authentication tokens for Google, Microsoft, Anthropic, Amazon and Cursor, sourced from 5,871 infected machines across 162 countries.
- For an SME, the rule is simple: an AI access offer significantly cheaper than the official rate should be treated as suspicious by default.
A black market growing with professional AI use
The more SMEs and large companies entrust tasks to tools like Claude, ChatGPT, Gemini or coding assistants like Cursor, the more the credentials granting access to these tools become valuable to cybercriminals. That is the finding from the Google Threat Intelligence Group: prices on underground marketplaces for stolen AI accounts more than doubled over the course of 2026. These accounts are not just used to chat with a chatbot for free: they grant access to powerful models, sometimes connected to the victim company's internal tools, making them a prime target.
Anthropic goes further in its report "Detecting and countering misuse of AI" and details a specific case that reveals the methods used.
The "Poison Claude" scheme: anatomy of a scam
An actor Anthropic identifies as GTG-50021 built a network of fraudulent resellers offering discounted access to Claude under the unofficial brand "Poison Claude".
December 2025 - August 2026
Activity detected
Ongoing
Funding the service
September 10, 2026
Anthropic report published
The mechanism is simple but effective: a customer looks for cheaper access to Claude Opus or Sonnet, finds an offer at 5-15% of the official price, pays in cryptocurrency and receives access that appears to work. In reality, their requests do not go directly to Anthropic: they pass through a relay server controlled by the fraudulent network, which can read, and potentially modify, every exchange, while also harvesting the victim's real Anthropic credentials along the way.
Key takeaway
An AI access offer that is "too cheap" is not just a financial scam. If it routes through an unofficial third-party server, all data sent to the model (source code, contracts, customer information) can be read, copied or modified without your knowledge.
Why this directly concerns your SME
An SME looking to save money on its AI tools might be tempted by "unlimited access" or "discounted license" offers found outside official channels, notably through unlisted resellers or social media groups. The concrete risks identified by Anthropic and Google fall into three categories:
Official channel
Unofficial reseller
The risk does not stop at the user who bought the fraudulent access: Anthropic recommends that organizations treat API keys and agent integrations with the same level of seriousness as production credentials, because that is exactly how attackers treat them. An API key left in a public code repository, an application container or a mobile app is an entry point just as valuable as an account stolen on the black market.
How to protect your SME right now
You don't need a dedicated security team to greatly reduce this risk. Four habits are enough for most SMEs:
Only buy through official channels
Treat API keys like critical passwords
Enable two-factor authentication and connection monitoring
Train your teams on the common-sense rule
Warning signs to watch for
| Signal observed | What to do |
|---|---|
| AI access sold at less than 30% of the official rate | Treat the offer as fraudulent by default |
| Payment required only in cryptocurrency | Strong red flag, unrelated to a legitimate subscription |
| Account shared between several unknown users | Risk of your data leaking to third parties |
| API key visible in a code repository, script or app | Revoke immediately and generate a new one |
| No identifiable invoice or contract in the vendor's name | Never connect sensitive data to it |
An encouraging signal
The detailed publication of this type of report by Anthropic and Google is good news in itself: major AI labs are now actively monitoring their own ecosystems and sharing their findings publicly, helping client businesses better protect themselves.
FAQ
How do I know if my professional AI account has been compromised?
Regularly check connection and usage logs from your provider's admin console (Anthropic, OpenAI or Google). Unusual activity (logins from unexpected countries, unexplained usage spikes) is the first sign to watch for.
Is a cheaper AI access offer always a scam?
Not necessarily if it comes from a reseller officially authorized by the vendor (often listed on their site). However, access at less than 30% of the official rate, paid in cryptocurrency or offered outside any identifiable channel, should be treated as suspicious by default.
What does an SME risk if it unknowingly uses fraudulent AI access?
Data sent to the model (code, contracts, customer information) can be read or copied by the operator of the fraudulent service. Its real credentials can also be stolen and resold in turn, exposing the company to further attacks.
What does Anthropic recommend businesses do to protect themselves?
Treat API keys and AI agent integrations with the same rigor as production credentials: secure storage, limited permissions, and purchasing exclusively through authorized channels.
Want to structure AI use in your company to avoid this kind of risk? Check out our resources on securing AI connectors and agents, or discover our guide to managing shadow AI in SMEs.


