AI News AI资讯 2h ago Updated 2h ago 更新于 2小时前 43

Metro Bank customer fights for £14,000 refund after AI-linked fraud 渣打银行客户追讨1.4万英镑退款,因AI关联欺诈事件

A Metro Bank customer lost £14,244 to fraudsters who used his stolen card details to purchase Claude credits without authorization The bank initially blocked only the first suspicious transaction (£90.90) and took over a day to fully freeze the card, allowing continued fraudulent charges Anthropic confirmed a coordinated gang used the victim's card details, banned the fraudulent user, and issued a full refund after the customer contacted support Metro Bank offered £300 in compensation, acknowled Metro Bank客户Zoli Rutter因银行卡信息泄露,被诈骗团伙用于购买Claude积分,损失14,244英镑 银行风控系统仅拦截首笔可疑交易(£90.90),未触发账户级冻结,导致后续欺诈交易持续通过 Anthropic确认无证据表明泄露源于其系统,已退款涉事用户并封禁欺诈账户 银行临时退款后由Anthropic承担最终损失,并提供300英镑服务补偿 事件暴露AI服务支付安全与银行风控协同的漏洞,客户拟向金融投诉服务申诉

62
Hot 热度
65
Quality 质量
58
Impact 影响力

Analysis 深度分析

TL;DR

  • A Metro Bank customer lost £14,244 to fraudsters who used his stolen card details to purchase Claude credits without authorization
  • The bank initially blocked only the first suspicious transaction (£90.90) and took over a day to fully freeze the card, allowing continued fraudulent charges
  • Anthropic confirmed a coordinated gang used the victim's card details, banned the fraudulent user, and issued a full refund after the customer contacted support
  • Metro Bank offered £300 in compensation, acknowledging service failures, while the customer plans to escalate to the Financial Ombudsman Service
  • This incident adds to a growing pattern of Claude-related fraud, including a US case where gift cards were purchased using compromised financial details

Why It Matters

This case highlights the emerging intersection of AI platform payments and financial fraud, raising critical questions about liability when third-party AI services become targets for organized fraud rings. It also exposes gaps in banking fraud detection systems, particularly around delayed card freezes and the complexity of distinguishing legitimate recurring payments from fraudulent ones.

Technical Details

  • The fraud exploited a stored debit card linked to an Anthropic/Claude account, with criminals making repeated micro-transactions between £90 and £200 to avoid immediate detection
  • Metro Bank's fraud detection system flagged the initial £90.90 transaction and contacted the customer, but only blocked that specific transaction rather than freezing the entire card
  • The bank's system sent a follow-up message stating the account "would be frozen," but this action was not implemented, allowing fraudulent transactions to continue for over 24 hours
  • Anthropic stated there is no evidence card details were compromised through its own systems, suggesting the data breach occurred through separate channels
  • The victim had been a legitimate paying customer at approximately £15/month for several months, using Claude for business invoice tracking and analysis

Industry Insight

  • AI companies like Anthropic must strengthen payment security measures and fraud detection on their platforms, as they are increasingly becoming the merchant of choice for criminal organizations seeking to monetize stolen card details through digital credit purchases
  • Financial institutions need to reassess their fraud response protocols, particularly the critical window between initial fraud detection and full card suspension, as delays of even hours can result in significant losses
  • The FCA's recent endorsement of Claude for financial sector AI experimentation stands in stark contrast to these security failures, underscoring the need for robust fraud prevention standards before AI tools are widely adopted in regulated industries

TL;DR

  • Metro Bank客户Zoli Rutter因银行卡信息泄露,被诈骗团伙用于购买Claude积分,损失14,244英镑
  • 银行风控系统仅拦截首笔可疑交易(£90.90),未触发账户级冻结,导致后续欺诈交易持续通过
  • Anthropic确认无证据表明泄露源于其系统,已退款涉事用户并封禁欺诈账户
  • 银行临时退款后由Anthropic承担最终损失,并提供300英镑服务补偿
  • 事件暴露AI服务支付安全与银行风控协同的漏洞,客户拟向金融投诉服务申诉

为什么值得看

该案例揭示了AI聊天机器人服务与金融欺诈的交叉风险,对AI服务提供者和金融机构的风控体系提出新挑战。事件处理过程暴露了银行实时欺诈检测的局限性,为行业改进支付安全协议提供实证参考。

技术解析

  • 欺诈模式:诈骗分子利用客户已存储的银行卡信息,在Anthropic平台批量购买Claude积分,单笔金额控制在£90-£200以规避大额交易警报
  • 银行风控机制:Metro Bank的欺诈检测系统仅拦截首笔可疑交易,但未触发账户级冻结,反映出风控策略在实时响应上的滞后性
  • 支付安全漏洞:客户已将银行卡绑定至Anthropic账户,但平台未实施二次验证或异常行为监测,使盗刷得以持续
  • 事件响应流程:银行在客户确认未授权后仅冻结单笔交易而非整个账户,导致欺诈交易持续通过

行业启示

  • AI服务集成金融支付需强化身份验证与交易监控,建议引入多因素认证和实时异常检测机制
  • 金融机构应优化欺诈响应协议,确保在客户确认未授权后立即冻结账户,而非仅拦截单笔交易
  • 监管框架需明确AI平台与银行在支付安全中的责任边界,推动建立跨行业欺诈信息共享标准

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Claude Claude Security 安全 Finance AI 金融AI LLM 大模型 Conversational AI 对话系统