:

HACKERS STEALING CLAUDE TOKENS FROM SUBSCRIBERS

AI DESK2 MIN READ
TUE, SEP 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Anthropic has warned users about unauthorized token theft after discovering hackers accessing Claude accounts. The breach prompted the AI company to alert subscribers about potential account compromises.

Security researchers at Anthropic identified a coordinated campaign targeting Claude subscribers' API tokens last month. The discovery came after a user reported unusual token consumption on his account despite no active work sessions. Investigation revealed that attackers gained access to multiple accounts and systematically drained tokens—the billable units users purchase for API access. The scope of affected accounts remains under review. How the Attack Works The hackers appear to be targeting users through credential compromise, likely via phishing or leaked credentials from third-party breaches. Once inside an account, attackers can consume tokens by making API requests, generating costs for legitimate users. Anthropic's Response The company has notified affected users and recommended immediate action. Anthropic advised subscribers to: - Rotate API keys immediately - Enable two-factor authentication - Monitor account activity and token usage regularly - Check billing for unauthorized charges Anthropric stated it is investigating the extent of the breach and has implemented additional monitoring to detect suspicious activity. Industry Context Token theft targeting AI API services has emerged as a growing threat as more companies integrate large language models into production systems. Compromised tokens can be monetized quickly by attackers through high-volume requests. Users should assume any exposed API key is compromised and regenerate credentials immediately. Those with unexpected charges may contact Anthropic's support team to dispute fraudulent token usage. The company has not disclosed the total number of affected accounts or estimated financial impact. Anthropic recommends checking account settings and billing history for signs of unauthorized access.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The NSA, CISA, and FBI jointly warned Tuesday that Chinese AI companies, including DeepSeek, are conducting large-scale technology distillation campaigns. The advisory accuses these firms of copying advanced AI models developed by Western competitors.

JUST NOWAI Desk

Cisco's President Jeetu Patel joined executives from OpenAI, Anthropic, and others in signing an open letter warning that AI-enabled cyberattacks will likely become more widespread and sophisticated. The same AI capabilities that boost productivity can be weaponized by malicious actors.

2H AGOAI Desk

Attackers have breached F5 BIG-IP APM devices to deploy a Linux rootkit capable of injecting malicious code directly into memory. The attack bypasses disk-based detection by intercepting PHP file loading.

3H AGODev Desk

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, requiring software vendors to disclose actively exploited flaws within 24 hours. Vendors must now prove exactly what shipped and when vulnerabilities were discovered.

3H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.