£14,000 was withdrawn to purchase Claude credits, and the bank approved the transaction.
A businessman in Sussex witnessed £14,244 vanish from his Metro Bank account. The funds were spent on credits for Claude, the AI chatbot he was already paying to use. Two failures occurred simultaneously: criminals exploited a chatbot to cash out stolen card information, and although his bank identified the first fraudulent transaction and alerted him, it subsequently allowed over £14,000 in additional fraudulent transactions to go through.
Zoli Rutter had been paying around £15 per month for Claude for several months, as he mentioned to Guardian Money. He utilized the chatbot to track and analyze business invoices. The fraudsters used the Metro debit card associated with his Anthropic account to purchase credits on the platform.
Upon detection, then overlooked
On June 19, Metro detected a suspicious transaction for £90.90 and sent Rutter a text to confirm whether he had authorized it. He replied that he had not. Shortly after, he received another message stating Metro would freeze his account. However, the bank only blocked that specific transaction and did not freeze the account altogether.
The fraudulent transactions continued, with each ranging from £90 to £200. Metro managed to block some but overlooked numerous others. The card was frozen the day after the scam started, but by then, over £14,000 had already been drained. The bank attributed the issue to the "complex nature of the fraud" and stated that it had processed some payments before fully blocking the card.
A chatbot as a cash register
The mechanics of this situation are unprecedented. A coordinated group used Rutter’s card details to purchase credits for Claude, according to Anthropic. The company asserted that it has no evidence suggesting that the details originated from their systems. They have also banned the user responsible for the fraud and advised anyone incorrectly charged to contact their support for a refund.
This incident was not isolated. In May, a Claude user in the U.S. reported to Guardian Money that fraudsters had purchased gift cards for the chatbot using his financial details. Others shared similar experiences on Reddit. AI credits are becoming a distinct target, reflecting a broader fraud economy emerging in the AI era, which banks are striving to address.
Who bears the cost
The process to obtain a refund became complicated. After Guardian Money reached out, Metro temporarily refunded Rutter as it sought a chargeback from Anthropic. Anthropic later issued a direct refund to him, allowing the bank to recover its temporary payment. Metro informed Rutter in a letter that he had not received the service they expect and offered him £300 in compensation.
Rutter plans to file a complaint with the Financial Ombudsman Service. Metro stated that it has implemented measures to prevent future delays in blocking cards.
This case arises during a busy period for Claude. Last week, the FCA seemed to endorse the chatbot, agreeing to grant firms in its high-tech sandbox access to it. This week, it was revealed that some users’ conversations with Claude were publicly visible online. Anthropic has also taken steps to verify the identities of its users.
The root issue remains straightforward: as more people save their cards to pay for AI services, those cards become attractive targets. The protective measures on both sides are still lagging behind.
Other articles
£14,000 was withdrawn to purchase Claude credits, and the bank approved the transaction.
Fraudsters utilized a Metro Bank customer's card to purchase £14,244 worth of Claude credits. The bank identified the initial charge as suspicious but subsequently allowed over £14,000 in additional transactions to go through.
