A gap between how platforms verify gift purchases and how they verify account changes has become a live account takeover channel, and the unauthorized charges are landing as chargebacks on the merchant. San Francisco station ABC7 reported on 24 June 2026 that a Martinez, California subscriber watched his bank flag a run of gift purchases in euros he never made. Two cleared before he could stop them, totaling around $315.
The attack never touches the password or email on file, because changing either one trips a security alert to the real account holder. Instead, whoever holds stolen credentials or a hijacked session buys gift subscriptions and routes the codes to an outside address, then resells them, often for crypto, before anyone notices. Gift purchases clear with fewer verification steps than account changes, so two-factor authentication that guards the login does nothing at the point of the transaction.
Any platform that stores a card on file and then adds a gift or credit feature has opened the same surface. For subscription and marketplace merchants the loss rarely stops at the fraud. The cardholder disputes the charge, and an account takeover claim arrives as a chargeback the merchant has to fight, distinct from friendly fraud where the buyer is the genuine account holder.
Why it matters
Treat the gift or add-on path as its own risk surface, not a lighter version of checkout. Step up verification on stored-card gift buys, throttle velocity per account, and flag codes routed to fresh external addresses. The cheapest place to stop one of these charges is before it authorizes, the same discipline as spotting fraud before it becomes a chargeback. Recurring billing merchants can fold it into their existing dispute controls.
- ABC7 News / KGO, “Martinez man says his AI was hacked as fraudulent charges racked up in euros on Claude account,” abc7news.com, 24 June 2026.
- PYMNTS, “Gift Card Loophole Gives Hackers a New Way to Cash Out,” pymnts.com, July 2026.

