:

CLAUDE CHATBOT USERS HIT WITH SURPRISE GIFT CARD CHARGES

AI DESK1 MIN READ
SUN, MAY 3, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Claude chatbot subscribers are reporting unauthorized gift card charges appearing on their credit card statements, with some families facing hundreds of dollars in mystery payments beyond their regular subscription fees.

David Duggan subscribed to Claude at $20 per month to leverage the AI chatbot's capabilities for medical questions and family organization. His experience took a costly turn when his wife discovered two $200 charges for gift cards on their credit card bill—charges neither had authorized. Duggan is not alone. Multiple Claude users have reported similar unauthorized transactions appearing alongside legitimate subscription payments. The pattern suggests either a vulnerability in Claude's payment processing system or fraudulent activity exploiting subscriber accounts. The incidents raise questions about payment security and account protection for AI service subscribers. Users report that resolving these charges has required manual credit card disputes and direct contact with support teams. Claude is Anthropic's widely-used AI chatbot, competing with ChatGPT and other large language models. The company has not yet issued a public statement addressing the reported charges or confirming whether a technical issue or fraud is responsible. Subscribers are advised to monitor billing statements closely and report unauthorized charges to their card issuers immediately.

■ SOURCES

The Guardian — Technology

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

YESTERDAYIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

YESTERDAYSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

YESTERDAYIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

YESTERDAYSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.