Detailed Analysis
A Claude account holder experienced a security breach in which unauthorized actors exploited their account to purchase £180 worth of Claude Max subscription gifts — specifically two £90 "Gift Max 5X - 1 month" transactions — before the account owner detected the fraud. The user responded appropriately by resetting credentials across their email and related accounts and immediately sought resolution through Anthropic's official support channel, which routes initial contact through a Fin AI Agent before escalating to human representatives. After persistent follow-up, the case was marked for human review, but four weeks elapsed with no substantive response, leaving the conversation in an apparently unassigned state within Anthropic's support system.
The situation highlights a meaningful gap in Anthropic's customer support infrastructure, particularly around account security incidents. While the company has grown rapidly as one of the leading AI model providers, its support apparatus — at least for consumer-facing Claude subscriptions — appears to lack the responsiveness expected when financial fraud is involved. The affected user's case involves a clear and documented monetary loss attributable to unauthorized account access, which would ordinarily warrant expedited handling. The apparent failure of the ticketing system to maintain assignment or trigger follow-up communication suggests either systemic gaps in support queue management or inadequate staffing relative to the growing Claude user base.
The user's instinct to escalate to [email protected] as a secondary channel reflects a common challenge in navigating AI company support structures, where AI-mediated front-ends can obscure or delay access to human resolution paths. This is a broader tension in the industry: companies deploy AI agents to handle support volume efficiently, but doing so risks creating dead ends for users with complex or urgent cases that require human judgment and accountability. Fraud recovery is precisely the category of issue where automated systems tend to underperform, as it requires coordination between account teams, billing systems, and potentially legal or trust-and-safety functions.
From a consumer protection standpoint, the user's reluctance to cancel their bank card — despite it being the bank's recommended mitigation — is understandable but carries its own risk calculus. Since no additional unauthorized transactions occurred, the compromise appears to have been account-credential-based rather than involving stored payment data being harvested for use elsewhere, which somewhat reduces the urgency of card cancellation. Nevertheless, the absence of a clear resolution pathway from Anthropic after a month is concerning for users who rely on Claude subscriptions and expect enterprise-grade accountability around billing security. The case underscores a recurring challenge for fast-scaling AI companies: product capability and commercial growth have outpaced the support and trust infrastructure needed to handle the inevitable edge cases of a large consumer user base.
Read original article →