A fake Claude reseller stole the credentials of the customers it claimed to serve
Anthropic reports that GTG-50021 sold supposed discounted Claude access, routed users to another model, installed credential-harvesting software and resold stolen Anthropic access.
Anthropic threat-intelligence reporting on a Russian- and Ukrainian-speaking group tracked as GTG-50021.
First seen
Sep 10, 2026
Case kind
incident
AI role
WITH AI
Claims
3
Reconstruction
The fraud works because the product being sold is itself access to AI. Customers believed they were buying discounted Claude service. Anthropic says the reseller silently sent their prompts to a different model while its client tooling harvested Anthropic credentials from the customer device.
That turns the customer into both the victim and the credential supplier. Stolen accounts can be sold to other resellers, used to run attacker workloads on the legitimate owner's bill, or used as attribution cover. Anthropic says related credential harvesters kept watching for replacement sessions after a victim reset compromised access.
The case belongs in an AI-security index because the account credential is no longer only a billing secret. It can become infrastructure for another intrusion campaign, an evasion mechanism and a commodity in a reseller market.
Mechanism & boundary
01
Advertise discounted model access
The operator attracts users looking for cheap Claude access.
Boundary: customer / reseller
02
Proxy prompts to another model
The service hides that the promised model is not being used.
Boundary: user expectation / actual routing
03
Install a credential harvester
Client tooling collects Anthropic credentials and authenticated sessions.
Boundary: local client / account secrets
04
Resell or reuse stolen access
Compromised accounts supply compute, resale value and cover.
Anthropic explicitly frames compromised AI access as loot, compute and cover.
reported findingsupported
Anthropic reports that the reseller tooling installed a credential harvester that stole Anthropic account credentials and sold them onward to other AI proxy resellers.
AI access should be purchased through trusted channels and protected like production credentials. Session tokens and API keys can fund and obscure attacker workloads after the initial theft.
Controls & mitigations
Use authorized model providers and treat third-party reseller clients as privileged software.
Rotate exposed AI session tokens and monitor for continued harvesting from compromised endpoints.
Apply workload-level anomaly detection so stolen credentials cannot silently fund offensive automation.
What remains unknown
The public source does not quantify how many reseller customers were compromised.
The current source set does not independently identify every downstream reseller that received stolen credentials.
DiggingBeagle. “A fake Claude reseller stole the credentials of the customers it claimed to serve.” First seen Sep 10, 2026. https://diggingbeagle.com/cases/a-fake-claude-reseller-stole-the-credentials-of-the-customers-it-claimed-to-serv/
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.