
A UK bank customer lost £14,244 after criminals used his debit card to buy credits for Anthropic’s Claude AI platform, even after he told his bank that the first suspicious transaction was not authorized by him.
The incident has raised questions about how banks respond when stolen card details are used repeatedly on a legitimate technology service.
The customer, Zoli Rutter, told Guardian Money that the fraud happened on 19 June. According to him, Metro Bank detected a £90.90 transaction and contacted him to ask whether he had authorised it. But Rutter said no, and the bank told him his account would be frozen. However, the suspicious transaction was blocked rather than the card being fully frozen.
More transactions followed, with individual payments ranging from £90 to £200. Some were stopped by the bank, but others went through before Metro Bank completely blocked the card the following day. By then, the total loss had reached more than £14,000.
How the Claude Charges Happened
Rutter had been paying about £15 a month for Claude and had previously linked his Metro Bank debit card to his Anthropic account. According to Anthropic, criminals used the compromised card details to purchase Claude credits.
Anthropic said it found no evidence that the card information came from a breach of its own systems. The company said a coordinated group had used Rutter’s card to make the fraudulent purchases and that the account involved had been banned. Anthropic also said customers affected by fraudulent purchases should contact its support team for refunds.
This matters because the transactions were being made to a genuine technology company that Rutter had previously paid. From the payment system’s perspective, they were purchases from a known merchant, but the problem was that the person making them was not the customer.
Where the Bank’s Protection Failed
Metro Bank has acknowledged that some payments were processed before the card was fully blocked. The bank said the case involved a third party that Rutter had previously made genuine payments to and whose card details had been stored, making the fraud more complex.
After Guardian Money contacted the bank, Metro temporarily refunded Rutter while pursuing a chargeback against Anthropic. Anthropic later refunded the money, meaning Metro’s temporary refund is due to be taken back. Metro also offered Rutter £300 in compensation and said it had introduced measures to prevent delays in blocking cards. Rutter plans to take his complaint to the Financial Ombudsman Service.
UK rules already provide protection for unauthorised payments, with the Financial Conduct Authority saying customers should report unauthorised transactions immediately.
AI Is Creating a New Fraud Problem for Banks
This case shows how existing fraud protections can become complicated when criminals use stolen financial details to purchase digital and AI services.
The banking system has rules for unauthorized payments, while AI companies have their own systems for handling accounts, credits, and refunds. Rutter’s case crossed both systems.
As AI services increasingly sell credits, subscriptions and other digital products, cases like this could force banks and technology companies to work more closely on fraud detection and payment disputes.
For banks and AI companies, the question remains how quickly they can build a system that can recognize whether a legitimate-looking digital purchase may be part of a much larger fraud.
