The Fake AI Reseller Trap: How Criminals Are Stealing Credentials Through Discounted AI Offers
Executive Summary
Kariba Security Group is warning small businesses about a documented criminal operation that poses as a legitimate AI reseller offering discounted access to services like Claude. When businesses sign up, their traffic is silently routed to a different AI model while credential harvesting software steals their account credentials and sells them to other criminal groups.
Anthropic's September 2026 threat intelligence report documents this operation specifically, tracked as GTG-50021. Customers believed they were getting discounted AI access. In reality, a credential harvester was stealing their authentication tokens and selling them onward to actors who used them to run attacks — at the victim's expense.
How the Attack Works
Step 1: The offer looks real
The criminal group sets up a professional-looking website offering discounted access to Claude or other frontier AI models — perhaps 40–60% below the official rate. The website uses real branding, appears professional, and may rank in search results for queries like "cheap Claude API" or "discounted AI access."
Step 2: You provide your credentials
To "activate" the discounted access, you're asked to provide your existing Anthropic credentials, or to create an account on their platform. Either way, your authentication information is now in the attacker's hands.
Step 3: You get responses — from a different model
The service works. You send prompts, you get responses. What you don't know is that you're not talking to Claude — you're talking to a cheaper or open-source model that the attacker is using to proxy your requests, while your real credentials are being used elsewhere for their operations.
Step 4: Your credentials are sold
Your stolen credentials are sold on Telegram channels and underground marketplaces to other criminal groups who use them to run cyberattacks, process stolen data, or conduct reconnaissance — all billed to your account.
Warning Signs
- The service is significantly cheaper than the official provider rate
- The service asks for your existing API key or account credentials to get started
- Response style, capabilities, or limitations feel inconsistent with the model you paid for
- The company has no verifiable corporate registration, physical address, or independent reviews
- Unexpected charges appear on your AI account after signing up
How to Protect Yourself
Buy directly from the provider
The most reliable way to know you are getting genuine Claude access is to purchase directly from Anthropic at anthropic.com. If you are considering a third-party reseller or integration, check Anthropic's official website for any published information about authorised partners before proceeding.
Never provide your credentials to a third-party service
If a service requires you to provide your Anthropic API key or login credentials to use it, you are giving that service the ability to impersonate you. This should require exceptional trust and verification before proceeding.
Be sceptical of significant discounts
Frontier AI models have genuine cost structures driven by the computing resources required to run them. Discounts substantially below market rate should prompt the question: how is this possible? A legitimate provider can answer that question clearly.
Look for independent verification
Legitimate businesses have verifiable histories, real customer reviews on independent platforms, and traceable corporate registration. A professional-looking website alone is not verification.
If You've Used a Suspicious Reseller
- Revoke all API keys immediately and create new ones following secure storage practices
- Change your Anthropic account password and enable two-factor authentication
- Review your account usage logs for the past 30–90 days for activity you didn't initiate
- Contact Anthropic support at support.anthropic.com and report what occurred
- Check your payment method for unexpected charges and dispute them with documentation
Checklist
- Purchase AI access directly from official providers only
- Never provide existing credentials to activate a third-party AI service
- Verify any reseller through independent sources before using
- Set up usage alerts to detect unauthorised account activity
- Rotate API keys immediately if you suspect credential compromise