Aiweekly.Co Underground AI Account Prices Surge Amidst Rising Cybercrime in 2026
Article Content
- •Underground prices for stolen AI accounts have more than doubled in 2026.
- •The vendor Poison Claude sells access to AI models at a fraction of official prices.
- •The operation uses free credits and cryptocurrency, posing significant risks to data security.
In 2026, the average prices for stolen AI accounts, including Claude, Gemini, and Cursor Pro, have more than doubled according to Google's Threat Intelligence Group. A vendor known as Poison Claude is selling access to Anthropic's Opus models at only 5-15% of the official pricing, utilizing free bonus credits from services like AWS Bedrock. This vendor operates by farming free credits and accepts cryptocurrency payments. The operation was traced through a 7 GB infostealer log dump shared on Telegram. The architecture of Poison Claude allows it to act as a proxy, enabling it to intercept and potentially modify user prompts and responses. The rise in underground marketplace activity indicates a growing illicit ecosystem targeting AI models. This trend is corroborated by reports of numerous safety incidents at companies like OpenAI and Anthropic. Neither Google nor Okta provided specific dollar ranges for the accounts, indicating a general increase in illicit activity rather than precise pricing.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track ACRStealer and Alibaba in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ClearFake WebDAV Infection Chain Targets Ukrainian Government with Amatera Stealer A cybersecurity investigation revealed a multi-stage malware operation targeting a Ukrainian government organization, utilizing a DLL named 'verification.google' executed from a WebDAV path. The attack, attributed to the threat actor UAT-10820, employs a combination of fake Google CAPTCHA prompts, Cloudflare Workers…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…