AI · 52 days ago
The break is not cheap Claude access. Once a gateway owns the API key and forwards the request, it can read the prompt before it reaches the model and keep the response on the way back. That turns third-party AI access into a standing exposure channel for anything staff paste into it.
Okta says Poison Claude has grown to about 900 paying users. The service uses pooled AWS Bedrock trial credits and fake accounts to route requests through its own servers, which makes the operator the real trust boundary, not Anthropic or AWS.
Any AI proxy or resold model access built this way creates the same problem: the reseller can collect prompts, internal data, and usage over time, and patching the model side does nothing to remove what already passed through the middle.
3 sources covering this story
Beware Cut-Price AI Services that Read Your Every Word
Learn how cut-price AI services like Poison Claude exploit cloud credits, expose sensitive prompts, and create serious data security risks for businesses.
Okta uncovered gray-market AI services selling cheap AI model access through fraudulent account registrations and abused cloud credits.
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Researchers find more than six illegal AI access ads, including Poison Claude, which claims 5-15% pricing while its operator can see customer prompts.
Part of the PlainSec briefing for 2026-08-10