Bottom line: The underground service "Poison Claude" sells discounted access to Anthropic models, with the operator having full visibility into all customer prompts, creating a significant data exposure risk for enterprises.
Security researchers have identified more than half a dozen underground services offering illegal access to AI models. One of them, "Poison Claude," promises discounted access to Anthropic models such as Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6 – while the operator apparently can read every incoming prompt from its customers.
Cybersecurity researchers have discovered more than six advertisements for illegal access to AI models on underground forums and messaging platforms. The service “Poison Claude” advertises itself as a broker for access to Anthropic’s language models, specifically naming the versions Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. The service is sold at prices significantly below Anthropic’s official API or subscription costs.
The fundamental technical principle behind such services typically relies on operators reselling legitimately acquired or stolen API keys or account credentials and routing their customers’ traffic through their own proxy infrastructure. This gives the operator full visibility into all prompts and responses that customers process through the service – including potentially sensitive corporate data, source code, internal documents, or personal information that users include in their queries.
For enterprises, this creates a dual risk: On one hand, employees often use such unofficial access points to save costs or bypass usage restrictions of official subscriptions, without being aware of the data exposure involved. On the other hand, confidential information processed through such channels can end up directly in the hands of cybercriminals, who may use it for extortion, resale, or targeted attacks. Since traffic runs through the operator’s infrastructure, there is also no control over whether or how long prompts and responses are stored.
CISOs should treat the use of unauthorized AI access within their organization as a distinct threat category and explicitly address it in shadow IT or shadow AI policies. This includes technical controls for detecting unusual API usage patterns, raising employee awareness about seemingly cheap AI access from underground sources, and enforcing the use of exclusively officially licensed and contractually secured access paths to LLM services. Organizations that find evidence of such services being used within their network should assume that data processed through these channels may have been compromised.
Source: thehackernews.com · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.