Reported by 1 source

The short version

  • A customer lost over £14,000 when fraudsters used stored card details to buy credits for the Claude AI platform despite his immediate denial of authorization.
  • Metro Bank admitted its systems failed to fully freeze the account after a suspicious transaction was flagged, allowing further unauthorized payments to process.
  • Anthropic confirmed the user was banned and refunded the charges, while the bank offered additional compensation for service failures.

A significant breach of financial security has come to light involving the misuse of artificial intelligence platform credentials by organized fraudsters. The incident centers on a businessman from Sussex who saw more than £14,000 drained from his Metro Bank account after criminals exploited stored payment information to purchase credits for Claude, an AI chatbot developed by Anthropic. This case underscores the growing complexity of digital fraud and the challenges financial institutions face in protecting customers when third-party technology services are involved.

The victim had been a paying subscriber to the AI service for several months, using it primarily to track and analyze business invoices. He maintained a debit card linked to his Anthropic account for these legitimate transactions. However, fraudsters managed to access his financial details and began making unauthorized purchases of platform credits. The initial suspicious activity was flagged by Metro Bank on June 19, when a transaction of approximately £90 triggered an automated security alert.

News Journal

Upon receiving a text message from the bank asking if he had authorized the charge, the customer immediately replied in the negative. In response, the bank stated that his account would be frozen. Despite this assurance, only the specific suspect transaction was blocked rather than the entire account or card. This partial restriction proved insufficient to stop the criminals, who proceeded to execute a series of smaller transactions ranging from £90 to £200.

The delay in fully securing the account allowed the fraud to continue for more than a day before Metro Bank finally froze the card completely. By that time, the total amount stolen had exceeded £14,000. A bank spokesperson acknowledged the failure, attributing the processed payments to the complex nature of the fraud involving a third party with whom the customer had previously conducted legitimate business. The institution admitted that its systems did not act quickly enough to prevent the loss.

This incident is part of a broader pattern of scams linked to AI tools. Other users in the United States and on social media platforms have reported similar experiences where gift cards or credits for chatbots were purchased using stolen financial data. While Anthropic has recently been highlighted by the Financial Conduct Authority for its role in helping firms experiment with advanced AI safely, this case reveals the risks associated with user account security.

Anthropic stated that a coordinated gang was responsible for using the customer’s card details to buy credits. The company emphasized that there is no evidence suggesting the compromised data originated from its own systems. The fraudulent user has been banned from the platform, and Anthropic confirmed that it refunds charges resulting from unauthorized purchases when reported through their support channels.

In the aftermath of the dispute, Metro Bank issued a temporary refund to the customer while pursuing a chargeback claim against Anthropic. After the AI company processed the refund, the bank indicated it would reclaim its temporary payment. Additionally, Metro Bank sent a letter acknowledging that the service fell short of expectations and offered £300 in compensation for the inconvenience and distress caused.

The customer has expressed dissatisfaction with the resolution and intends to file a formal complaint with the Financial Ombudsman Service. He argues that the bank’s failure to freeze his account immediately after he denied authorization constitutes a significant service failure. Metro Bank claims it has since implemented steps to prevent delays in blocking cards during similar incidents.

Regulatory guidance suggests that customers affected by unauthorized card fraud should contact their banks immediately to request refunds. Under current rules, refunds are typically expected within one business day. This case highlights the need for clearer protocols when dealing with third-party digital services and the importance of robust real-time monitoring systems to prevent partial freezes from becoming loopholes for criminals.

As AI adoption accelerates across various sectors, the intersection of financial security and technology platform vulnerabilities remains a critical concern. Financial institutions must adapt their fraud detection mechanisms to account for the unique risks posed by subscription-based digital services. Until then, customers remain exposed to sophisticated scams that exploit gaps between authorization alerts and actual account protection.

Sources behind this briefing

Go to the original reporting