← Reddit

Claude account hacked. Pretty sure it’s secure now. Should I keep using it?

Reddit · FugitiveActual · July 27, 2026
A Claude account owner's account was compromised, with the attacker upgrading the subscription to Max and generating approximately £100 in fraudulent charges. The user discovered malware on their PC, reported the fraudulent charges to American Express, changed their Google password, and contacted Anthropic Support, though they remained awaiting a response 12 hours later. Unable to manually downgrade until the billing period ends, the user expressed uncertainty about whether continued use of the temporarily Max-tier account would complicate the investigation.

Detailed Analysis

A Reddit user's account compromise highlights a growing concern among Claude subscribers: the security implications of "Sign in with Google" authentication when the underlying Google account or device is compromised. In this case, the user's PC was infected with malware, which appears to have facilitated unauthorized access to their Google credentials and, by extension, their linked Claude account. Once inside, the attacker upgraded the victim's subscription from Pro ($20/month) to Max 20x—a premium tier priced significantly higher and offering substantially more usage—then rapidly consumed the expanded quota before racking up nearly £200 in additional fraudulent charges. This pattern suggests the attacker was likely using the compromised account for high-volume API-style usage, possibly reselling access or running automated tasks, rather than casual personal use.

The incident underscores a structural challenge facing AI companies as their platforms become more valuable and thus more attractive targets: the monetary incentive for account takeover has risen alongside subscription tiers that can cost hundreds of dollars monthly. Unlike a compromised email or social media account, a hijacked AI subscription account represents both a direct financial loss (fraudulent charges) and a potential vector for abuse of the underlying service—whether that's generating content, running scaled automation, or circumventing rate limits by hijacking someone else's paid tier. Anthropic, like many SaaS companies, currently relies on standard support ticketing (AI chatbot triage escalating to human review) for these situations, which the user found frustratingly slow—12+ hours without human response for what is effectively a financial fraud and security incident deserving urgent handling.

The user's dilemma—whether to keep using the account while billing status remains in limbo—reflects a broader tension in how AI companies structure account security and billing recovery. Because downgrades can only take effect at the end of a billing cycle, the victim is stuck paying for or being associated with a Max-tier plan they never wanted, while also worrying that continued use could complicate fraud investigation or reimbursement. This is a common pain point across subscription services: security teams need to verify legitimate use patterns before issuing refunds, but customers have no clear guidance on whether "business as usual" usage helps or hurts their case. Anthropic does not appear to have published specific guidance for users in this exact situation, leaving customers to guess at best practices during an active fraud investigation.

More broadly, this incident is a symptom of AI companies scaling faster than their trust-and-safety and account-security infrastructure can keep pace. As tools like Claude become daily-use productivity software—embedded in professional workflows the way this user describes—the cost of account compromise, downtime, or slow support response grows correspondingly higher. Competitors like OpenAI have faced similar scrutiny over account security, subscription fraud, and slow support responsiveness as their user bases have exploded. For users, the practical lessons are the standard ones for any high-value SaaS account: enable two-factor authentication independent of a single Google sign-on, monitor for unusual billing changes immediately, and treat consumer malware hygiene as directly tied to AI account security, since compromised endpoints are increasingly the weak link enabling unauthorized access to increasingly costly cloud AI subscriptions.

Read original article →