Fake Claude reseller proxies traffic to other models and steals Anthropic credentials

ns123abc · x · 2026-09-11

A report describes a fake Claude reseller offering "discounted Claude access" while silently proxying traffic to different models, with a credential harvester installed that stole customers' Anthropic credentials — then resold to other fraudulent resellers.

The same thread also cites Shinyhunters abusing stolen Claude access at an EV charger company to remotely control charging current in customers' homes as part of a supply chain attack involving 200 organizations.

Related event: ShinyHunters Scanned 1.8M Android Apps and Hijacked EV Chargers(3 posts)→

Original post →

More from Safety

Safety channel →