A third-party seller distributed discounted Claude AI subscriptions while capturing all user conversations, exposing customer privacy risks.
A reseller operating under the name "Poison Claude" has been caught running what amounts to a digital wiretapping scheme. The operator purchased legitimate access to Anthropic's Claude AI tool and then resold subscriptions to customers at reduced prices. The catch? Every single conversation between customers and Claude passed through the reseller's systems first, giving the operator complete visibility into private prompts, questions, and interactions.
Think of it like buying phone service from someone who wasn't the actual phone company. You save money, but the middleman can listen to every call you make. That's essentially what happened here—customers thought they were getting a deal, but they were actually handing over their confidential information to an unknown third party.
This incident highlights a fundamental tension in how AI services get distributed. When people hunt for discounts online, they often don't consider who's standing in the middle of the transaction. In this case, the reseller had access to everything customers typed into Claude—including:
For businesses especially, this represents serious data leakage. An employee saving money on an AI tool could inadvertently expose their employer's proprietary information to a stranger running an unauthorized service. The reseller could copy conversations, analyze them for valuable insights, or even sell access to that data elsewhere.
The reseller wasn't hacking anything—they simply created an intermediary layer. Customers would connect to Poison Claude's system, which then relayed requests to the real Claude service while logging everything in between. It's a man-in-the-middle attack, but one that customers willingly participated in because they saw lower prices.
The real danger isn't just financial. It's the trust violation: people believed they were using an official service when they were actually routing sensitive conversations through an unknown operator.
If you use Claude or any AI service, follow these straightforward steps:
This story serves as a reminder that convenience and savings sometimes come with hidden costs. Saving $10 a month on AI access isn't worth exposing your company's roadmap, your personal health questions, or your financial planning to strangers. The lesson applies to any online service: verify the source before you share sensitive information.
For businesses, this should trigger conversations about which tools employees can use and where they're allowed to purchase them from. IT departments should consider blocking access to unauthorized reseller platforms entirely.
Always remember: if you're not paying with money, you might be paying with your data.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →