Someone else is paying for your AI subscription — and reading everything you type into it

You found a deal online: Claude Pro for $8 a month instead of $20. ChatGPT Plus for half price. DeepSeek access that runs faster than the free version. You paid through Telegram. You got a login link. It works perfectly.

Here's what you didn't get told: the person who sold you that access can see every single thing you ask the AI. Every draft email. Every business plan. Every medical question you were too embarrassed to ask a real doctor. Every private conversation you assumed was between you and the machine.

They're not hacking you. You're just both using the same account — and they got there first.

The new privacy violation that doesn't require a breach

This isn't credential stuffing or phishing. It's simpler and worse. Criminals are buying or stealing API tokens and enterprise AI accounts, then reselling access to those accounts at a discount. When you use that discounted service, you're authenticating through their infrastructure. Everything you send to the AI passes through their systems first.

Security researchers just documented half a dozen of these services operating in plain sight — some with Telegram channels, customer support, and refund policies. One service called "Poison Claude" offered discounted Claude API access while logging every prompt customers sent. Another let users query an AI meeting assistant's database to pull transcripts from thousands of corporate video calls.

The AI itself has no concept of whether you're supposed to be there. It doesn't know if you're User #1 or User #47 on the same stolen enterprise license. It just answers. There's no alert. No security warning. No notification sent to anyone.

Your AI assistant can't tell the difference between you and the stranger reselling your access.

Why this is exploding right now

Three things converged in the last twelve months. First, AI went from experimental to essential — millions of people now depend on ChatGPT, Claude, and Copilot for daily work. Second, those services got expensive. A single enterprise API token can cost thousands per month, and even individual subscriptions add up when you're paying for three different AI tools. Third, there's now a massive supply of stolen credentials.

Researchers found 321 exposed API tokens for n8n — a workflow automation tool that connects to AI services — sitting in public GitHub repositories. Each token was a working key to someone's live AI instance. In another case, a misconfigured Firebase database exposed meeting transcripts, participant lists, and join links for an AI notetaker used in government and corporate calls. One query could pull anyone's meetings.

The gap between what AI costs and what people will pay created a black market. The gap between who owns an account and who uses it created a surveillance problem nobody designed these systems to prevent.

What to actually do about this

1. Never buy discounted AI access from third parties. If it's cheaper than the official price and sold through Telegram, Discord, or an unfamiliar website, you're either using a stolen account or routing your prompts through someone else's infrastructure. Pay the real price or use the free tier.

2. Check where your AI login actually goes. Before you enter credentials or click an access link, look at the URL. If it's not the official domain — openai.com, claude.ai, the actual vendor site — stop. Phishing pages and reseller dashboards look identical to real ones.

3. Revoke and rotate any API tokens you've shared or stored in code. If you're a developer or power user with API keys, assume any token committed to GitHub, pasted in Slack, or saved in a config file is now public. Rotate them. The next person who finds that token can resell access to your account.

4. Audit your AI meeting tools and browser extensions. If you use an AI notetaker, transcription service, or assistant that joins your video calls, check its permissions and privacy policy. Some of these tools store everything in databases that one misconfiguration exposes to the internet.

5. Treat AI prompts like you treat text messages to a stranger. Until the industry fixes the architecture, assume anything you tell an AI could be visible to someone else. Don't put sensitive personal information, proprietary business data, or private medical details into a tool where you can't verify who else has access.

What have you found?

Have you ever used a discounted AI service and later wondered who was actually running it? Seen your meeting transcripts show up somewhere unexpected? Discovered an old API token you forgot you published?

Identity Decoded publishes every week at identity-decoded.com

Reply

Avatar

or to participate