In the cutthroat world of AI development, where a single query can cost fractions of a penny but millions of queries can bankrupt a startup, the promise of a 90% discount on Anthropic’s Claude model is almost irresistible. But as researchers from Okta have discovered, the service known as “Poison Claude” is not a legitimate bargain — it is a sophisticated fraud operation that has already ensnared approximately 900 paying customers who handed over cryptocurrency for access they believed was too good to be true. This scheme, which exploits Amazon Web Services free credit system through a factory of fraudulent accounts, represents a new and dangerous frontier in AI-related cybercrime.
The Poison Claude Scam: How Fake AI Discounts Work
Poison Claude marketed itself as a cut-price gateway to Anthropic’s flagship AI models, including Claude Opus and Sonnet, offering access for between 5% and 15% of the official pricing. For developers and businesses burning through tokens at an alarming rate, the financial appeal was obvious. However, the mechanism behind the discount was entirely parasitic — and illegal.
The service exploited a fundamental feature of Amazon’s cloud computing platform, AWS Bedrock, which hosts Anthropic’s Claude models for third-party developers. Amazon encourages new customers to try its services by offering free credits — typically around $200 worth of Claude usage per new account, contingent on completing setup tasks. Poison Claude spotted that nothing technically prevented an actor from creating thousands of fake accounts to harvest these credits repeatedly.
By generating a vast pool of fraudulent AWS accounts, each with its own identity and email address, the operators accumulated tens of thousands of dollars in free credits. When a paying customer submitted a query to Poison Claude, the system silently routed it to the real Claude API through whichever fraudulent account still had credits remaining. When one account was exhausted, the system automatically switched to the next. The customer believed they were receiving a discounted service; in reality, Amazon was unknowingly footing the bill for credits granted to people who did not exist.
The Scale of the Operation
The Poison Claude website was brazenly upfront about its business model, effectively explaining how it undercut official pricing. This candor did not deter customers. According to Okta’s research, approximately 900 individuals and organizations signed up for the service, paying in cryptocurrency to maintain anonymity. The operation was run from a web hosting service in Mumbai, India, and the operators attempted to shield their infrastructure behind Cloudflare — though researchers discovered an exposed API endpoint that revealed active user counts and system activity.
A parallel operation called EcoMagent employed a similar strategy, offering AI startups up to $350,000 in Google Cloud credits through fraudulent means. The technique is not limited to a single cloud provider, suggesting a broader underground economy built on abusing the very incentives designed to grow legitimate AI adoption.
What Is the Real Danger: Data Theft Through AI Proxy Services
The immediate financial fraud against Amazon and Anthropic is significant, but the far greater risk lies with the customers who paid for Poison Claude. Every query, prompt, document, and piece of code submitted to the service passed through Poison Claude’s own servers before being forwarded to the real Claude API. This means the operators had full visibility into everything their customers typed.
Consider what users trust AI models with today: source code containing API keys and database credentials, business plans and strategic documents, legal contracts, medical queries, personal correspondence, and proprietary research. All of this data was handed directly to an anonymous criminal operation running a service from a Mumbai hosting provider with demonstrably poor security. The researchers found that Poison Claude had left an API endpoint exposed, allowing simple commands to reveal the number of active users and system architecture.
What did Poison Claude plan to do with this accumulated data? The possibilities are grim. The operators could sell it on underground forums, use it to train competing AI models, harvest credentials for targeted attacks, or simply leak it. The service itself was already advertising on criminal forums, suggesting a sophisticated operation with multiple revenue streams beyond the initial subscription fees.
The Erosion of Security Advice
The Poison Claude scheme presents a fundamental challenge to decades of cybersecurity training. For years, users have been told to verify they are on a legitimate website, check for valid SSL certificates, and ensure URLs are authentic. In this case, the entire premise of that advice collapses — because the data is being intercepted not through a fake login page, but through a legitimate service that is acting as a malicious middleman.
This is not a sophisticated zero-day exploit or a complicated man-in-the-middle attack. It is a simple intermediary service that the customer voluntarily pays to use. The only vulnerability is the customer’s willingness to trust a stranger with their most sensitive information in exchange for a discount. As security researcher and podcast guest Lianne Potter observed, the rationalization is familiar: “We’re so distanced from the victim — in this case, Anthropic — we see them as these massive companies with massive revenues. My little tiny bit of crime is not going to impact them.”
The Greatness Phishing Kit: Device Code Phishing Targets Microsoft Users
While Poison Claude exploits cloud credit systems, a separate threat called the Greatness phishing kit demonstrates an equally troubling evolution in credential theft. Greatness, a phishing-as-a-service platform available on underground markets, has adopted a technique known as device code phishing that makes traditional security advice nearly useless.
Device code phishing weaponizes a legitimate Microsoft authentication flow. Microsoft allows users to log into devices that cannot easily display a traditional login screen — think hotel room smart TVs, conference room equipment, or IoT devices — by entering a short code displayed on the device into a standard Microsoft login page. Greatness turns this convenience feature into a phishing vector.
The attack works as follows: A user receives an email that appears to be a genuine Microsoft security alert, asking them to verify their identity by entering a code. The email contains a real Microsoft URL with valid certificates. The user’s password manager recognizes the domain as authentic. The user enters the code provided in the email, which was actually generated by the attacker’s Greatness toolkit. Microsoft, believing the user wants to authenticate a third-party application, asks for permission to connect that application to their account. The user, thinking they are simply completing their own login, approves the request.
In that moment, the user has granted the attacker’s OAuth application full access to their Microsoft account — including email, files, and the ability to impersonate them across their organization. The attacker never needed the user’s password. They simply needed the user to volunteer permission.
Why Traditional Security Advice Fails
The Greatness phishing kit renders much conventional advice obsolete. The URL is legitimate. The SSL certificate is valid. The password manager is happy. There is no suspicious domain, no misspelled brand name, no grammatical errors. The only sign of trouble is that the user did not initiate the authentication flow themselves. The advice from researchers at Cisco Talos, who documented this campaign, is stark: “If you didn’t start a login, don’t finish it — even if the page looks real.”
For enterprises, the recommended mitigations include disabling device code flow entirely if it is not needed for conference room equipment or other legitimate use cases, restricting OAuth application consent to approved administrators, and deploying monitoring tools that can detect unusual consent events. But the deeper implication is that organizations must fundamentally shift their user education programs. Trusting a legitimate website is no longer sufficient when attackers can weaponize legitimate authentication flows against their victims.
The Psychology of Cybercrime Rationalization
Both Poison Claude and Greatness exploit not just technical vulnerabilities but psychological ones. When asked why individuals sign up for services they know are fraudulent, researchers point to a familiar pattern of rationalization. The victims are large corporations that the user perceives as faceless, wealthy, and perhaps even exploitative themselves. Stealing from Amazon or Anthropic, the reasoning goes, is not the same as stealing from a local business or an individual.
This moral distancing allows users to justify behavior they would never consider in other contexts. The same person who would not shoplift from a corner store might happily use a stolen Netflix account or pay for a cut-rate AI service sourced from fraudulent cloud credits. The distance between the action and the perceived harm grows with the size and impersonality of the target organization.
But the consequences are real. Poison Claude’s exposed API endpoint and Mumbai hosting base suggests security practices that are far from enterprise-grade. Researchers were able to query the system and receive responses showing active user counts — a clear warning that the operators were not prioritizing data protection. The information flowing through this pipeline is not just metadata; it is the raw intellectual property, credentials, and private communications of paying customers.
Cloudflare’s Role and the Limits of Platform Enforcement
Despite researchers reporting Poison Claude to Cloudflare for hosting and proxying the fraudulent service, Cloudflare declined to take action. This is not an isolated incident; cybersecurity observers have noted that Cloudflare has been reluctant to shut down services that facilitate criminal activity, citing its role as an infrastructure provider rather than a content arbiter. The decision means that Poison Claude remains operational, and the approximately 900 users who signed up are still vulnerable to data exfiltration.
The incident highlights a gap in the enforcement ecosystem. Cloud providers like Amazon and Google can detect and shut down fraudulent accounts, but doing so requires monitoring for patterns that indicate systematic abuse of free credit programs. Meanwhile, the intermediaries that route traffic and protect websites from DDoS attacks may not have the incentive or legal mandate to police the activities of their customers.
Protecting Against AI Proxy Fraud and Device Code Phishing
For organizations and individual developers navigating this landscape, several practical steps emerge from these incidents. First, never use AI services offered at dramatic discounts through unofficial channels. The cost savings are not worth the data exposure. Stick to official APIs from Anthropic, OpenAI, Google, or Microsoft, even if the pricing is higher. The premium is effectively an insurance policy against data compromise.
Second, implement strict controls around OAuth application consent within your organization. Disable device code flow unless it is actively needed. Restrict the ability to approve third-party application connections to authorized administrators. Monitor consent events for anomalies. These controls will not stop every phishing attempt, but they will significantly raise the bar for attackers using the Greatness methodology.
Third, update user security training to address the new reality. The old advice of “check the URL” is no longer sufficient. Users must understand that they can be phished on legitimate websites through legitimate authentication flows. The fundamental principle — never complete a login process you did not initiate — must become as ingrained as the instruction to avoid clicking suspicious links.
The Broader Implications for AI Security and Trust
The Poison Claude incident is not an isolated curiosity but a harbinger of a larger problem. As AI models become more expensive to run at scale, the incentive to find cheaper access routes will only grow. The fact that attackers can exploit cloud free credit programs so effectively suggests that the major cloud providers may need to tighten their onboarding verification processes — perhaps requiring validated payment methods or identity verification before granting substantial free credits.
More broadly, the willingness of nearly a thousand people to pay for a service they knew was fraudulent reveals a troubling erosion of trust and ethical boundaries in the AI economy. These customers are not naive consumers; they are developers and businesses who actively sought out a deal they knew was too good to be true. The rationalization that “Amazon can afford it” may be psychologically convenient, but it ignores the real data risk that these customers assumed.
The convergence of AI affordability pressures, cloud credit abuse, and sophisticated phishing techniques like device code attacks creates a perfect storm for organizations trying to secure their digital operations. The attackers are not just stealing credentials or processing power — they are inserting themselves as intermediaries in the data pipeline, capturing everything that flows through. In an era where every company is racing to integrate AI into its products and workflows, the security of that AI supply chain has become a board-level concern.
The lesson from Poison Claude and Greatness is that the cheapest option is rarely the safest. In the business of AI, as in so many other things, you get what you pay for — and sometimes, you pay for it with far more than money.