Claude chatbot subscribers are reporting unauthorized gift card charges appearing on their credit card statements, with some families facing hundreds of dollars in mystery payments beyond their regular subscription fees.
David Duggan subscribed to Claude at $20 per month to leverage the AI chatbot's capabilities for medical questions and family organization. His experience took a costly turn when his wife discovered two $200 charges for gift cards on their credit card bill—charges neither had authorized.
Duggan is not alone. Multiple Claude users have reported similar unauthorized transactions appearing alongside legitimate subscription payments. The pattern suggests either a vulnerability in Claude's payment processing system or fraudulent activity exploiting subscriber accounts.
The incidents raise questions about payment security and account protection for AI service subscribers. Users report that resolving these charges has required manual credit card disputes and direct contact with support teams.
Claude is Anthropic's widely-used AI chatbot, competing with ChatGPT and other large language models. The company has not yet issued a public statement addressing the reported charges or confirming whether a technical issue or fraud is responsible.
Subscribers are advised to monitor billing statements closely and report unauthorized charges to their card issuers immediately.
PaperCut has released a second emergency security update for its NG and MF print management software after researchers discovered bypass methods for the initial fixes. The vulnerabilities are currently being exploited in the wild.
A 68-year-old has been sentenced to over six years in prison in the U.K. for operating an illegal IPTV service that generated £980,812 ($1.3 million) over three years.
A detailed analysis examines how the internet has shifted toward predatory practices, drawing significant engagement from tech community members on Hacker News with 227 points and 120 comments.
A critical vulnerability in the popular GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on hosting servers. The maximum-severity flaw requires immediate patching.