Researchers reported that Poison Claude, a gray-market service, sold heavily discounted access to Anthropic’s Claude models by routing customer requests through fraudulently created cloud and AI-provider accounts funded with free promotional credits. Okta Threat Intelligence said the service advertised unlimited or bundled token access at roughly 5% to 15% of official pricing, accepted cryptocurrency, and told users to redirect Claude Code or Anthropic-compatible API traffic to infrastructure controlled by the operator rather than Anthropic’s official endpoint. A misconfigured status page briefly exposed 881 total users and 872 active users, suggesting broad adoption, and investigators linked related infrastructure to a Hostinger server in Mumbai while the main domain remained behind Cloudflare.
Okta also identified a similar service, Ecomagent[.]in, which appeared to use Google Cloud startup credits and Vertex AI to provide discounted Anthropic model access, while Poison Claude was tied to pooled accounts using AWS Bedrock bonus credits. The activity was linked to wider automated account fraud against AI platforms, including large-scale fake sign-ups using VPNs and residential proxies, and researchers warned that customers of such proxy services risk prompt exposure, model substitution, and sudden service loss if upstream providers suspend the fraudulent accounts. Anthropic responded by strengthening identity verification and abuse detection, and Okta said it notified Cloudflare, Anthropic, AWS, and Google Cloud about the infrastructure and abuse patterns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Earlier in 2026, Anthropic accused DeepSeek, Moonshot AI, and MiniMax of running industrial-scale campaigns to extract Claude’s capabilities. This is cited as prior context for abuse targeting access to Anthropic models.
Anthropic restricted subsidiaries from offering services to unsupported regions such as China. Okta cited this September 2025 move as part of the backdrop for later gray-market resale of Claude access.
Okta Threat Intelligence notified Cloudflare, Anthropic, AWS, and Google Cloud about the infrastructure and abuse patterns documented in its investigation. The notifications covered the observed gray-market resale services and associated account-fraud activity.
After responsible disclosure, Cloudflare placed a phishing warning in front of the Poison Claude main website. Okta also said Cloudflare appeared to decline action on the separate Poison Claude API domain.
The previously exposed Poison Claude API status endpoint was later fixed, closing the misconfiguration that had revealed user counts and service status data. This remediation occurred after Okta’s discovery.
Anthropic responded to abuse by introducing Persona-based identity verification for some new accounts, requiring government ID and selfie checks. The company also built fingerprinting systems to detect abuse originating from Asian time zones.
Okta separately tracked more than 105,000 fraudulent sign-up attempts against an AI video platform’s free trial from 251 IP addresses associated with VPNs and residential proxies. The activity was concentrated in Lebanon, Indonesia, and Thailand and was assessed as consistent with attempts to bypass regional restrictions.
Researchers identified Ecomagent.in as a similar gray-market service offering discounted access to Anthropic models and GPT Codex 5.5. Response metadata tied the service to Google Vertex AI, suggesting use of fraudulently obtained Google Cloud startup credits rather than direct Anthropic access.
Investigators traced the related Poison Claude endpoint api.claudeopus.shop to a Hostinger server in Mumbai, despite the main Poison Claude domain being masked behind Cloudflare. This tracing occurred before the exposed endpoint was patched.
Okta found a misconfigured unauthenticated Poison Claude API status endpoint at api.claudeopus.shop/api/status. The endpoint exposed operational data showing 881 total users and 872 active users at the time of discovery.
Okta Threat Intelligence identified Poison Claude as a gray-market service reselling discounted access to Anthropic Claude models by routing usage through pooled fraudulent cloud or AI-provider accounts funded with promotional credits. The service advertised access to multiple Claude models at roughly 5% to 15% of Anthropic’s official pricing and accepted cryptocurrency payments.
Researchers discovered more than half-a-dozen advertisements on underground cybercrime forums and messaging platforms offering illegal or unauthorized access to commercial AI models. Poison Claude was identified as a prominent example among these services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceitpro.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceokta.com
Open sourceanthropic.com
Open sourcesupport.claude.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.