Go to Member Center

Anthropic Refunds Claude Users After Stolen Sessions Drain Usage

anthropic claude fraud subscription billing usage-based pricing Aug 31, 2026

The incident shows how usage-based subscription models can create new fraud risks when account access itself carries monetary value.

Anthropic is refunding unauthorized charges after stolen Claude login sessions were used to access customer accounts and consume their usage.

The company described the activity in an email sent to an affected user that was shared on Reddit and reported by BleepingComputer.

According to the email, malware already on users' computers captured active Claude login sessions. A bad actor then used those sessions to access accounts and consume Claude usage.

Anthropic told affected customers that unexplained usage could appear as limits that reset and then drain even when the subscriber wasn't using Claude.

The company said it signed affected users out, removed saved payment methods and would refund charges it identified as unauthorized.

Anthropic has not disclosed how many users were affected or how much unauthorized usage or spending occurred.

Usage itself had value to steal

Claude's paid plans include usage allowances that reset over time.

Customers on several paid plans can also enable usage credits to keep using Claude after reaching their included limits. That additional usage is charged separately.

So unauthorized access can cost a customer even when it doesn't immediately create a new charge.

An attacker can consume usage already included in the subscription. If additional paid usage is enabled, the attacker can also use purchased credits or create additional usage costs.

Anthropic told affected users that the malware did not come from Claude. The affected computers were likely already infected with malware capable of collecting passwords and active login sessions.

The company's investigation is ongoing.

Insider Take

As more subscription companies add usage-based pricing, bad actors have another place to look for value. If usage has monetary value, unauthorized access can consume something the subscriber has already paid for or create additional costs.

For operators offering usage-based products, or considering them, this adds another kind of fraud exposure to the model.

What happens when unauthorized activity consumes an allowance? What if it uses prepaid credits or runs up additional charges? And how quickly can unusual usage be identified before the customer discovers it?

Anthropic's experience shows where the risk can move as more value is tied to usage. As more value moves into usage, bad actors will have more incentive to find ways to steal it.

Related Member Resources

For more on how fraud is changing across subscription businesses and where new risks can emerge:

Sources