ft.com web signal

Google: Underground AI Account Prices More Than Doubled in 2026

TL;DR

  • Google's Threat Intelligence Group says average underground marketplace prices for stolen Claude, Gemini and Cursor Pro accounts more than doubled during 2026.
  • Okta traced a vendor branded Poison Claude selling Anthropic's Opus 4.6-4.8 and Sonnet 4.6 at 5-15% of official per-token pricing.
  • The vendor stocks its pool by farming free bonus credits like AWS Bedrock's $100 welcome credit and accepts payment in cryptocurrency.

Underground marketplace prices for stolen AI accounts more than doubled during 2026, according to Google Threat Intelligence Group findings reported by the Financial Times. GTIG says buyers are concentrating on Claude and Gemini credentials, plus autonomous coding IDEs like Cursor Pro and Devin.

One vendor, branded Poison Claude, advertises Anthropic's Opus 4.6, 4.7 and 4.8 models plus Sonnet 4.6 at 5-15% of the official per-token price, according to Okta's threat intelligence team. Okta says the vendor stocks its pool by farming free bonus credits, including the $100 welcome credit on AWS Bedrock, and accepts payment in cryptocurrency. Its analysts traced the operation via a 7 GB infostealer log dump published to a Telegram channel on August 2, 2026.

The catch is architectural. Poison Claude sits as a proxy between the buyer and Anthropic, so Okta's researchers say it can "see every prompt and response," including code, contracts, and personal data, and can "modify responses in transit without the customer being able to tell."

"There's an entire illicit ecosystem to try to gain access to Claude and other models," Jacob Klein, Anthropic's head of threat intelligence, told CNBC. GTIG's tracker documents a related shift: in May 2026, operators of the ACRSTEALER infostealer pushed rules to grab the secrets.json file used by Cline (formerly Claude Dev) and the config.yaml file used by Continue AI, which store plaintext API keys. That fits a wider week of coverage, alongside Axios's report of tens of thousands of frontier-model safety incidents at OpenAI and Anthropic.

Neither GTIG nor Okta publishes a per-account dollar range, so "more than doubled" is a direction rather than a price sheet.