
I haven't been on ActiveRain for a few weeks, and I'm really disappointed about that. But I had a hell of a July!
About 4 weeks ago, I logged into Facebook. Nothing abnormal- just checking on my business pages, etc.
The very next day, about 24 hours later-- I was permanently banned from Facebook for "launching fraudulent ad campaigns." It turns out that someone posing as me launched dozens of ad campaigns for bogus products, using bogus credit cards. The hacker wasn't interested in my posts or my friends, the hacker just needed any account so that they could get it and launch their fraudulent ads selling (and this is important) AI slop / Fake products.
Now, over the years, I will admit: When people say "my Facebook account was hacked," I immediately think it's bullshit. I have been very judgmental over the years about this, and I feel pretty dumb now. How could your Facebook account be hacked? Don't you have to paste in a code when logging in from an unknown device?
Then Came More Bans
The next day, I was banned from my favorite AI platform- that I use for everything- which is Claude.ai (Anthropic). They literally will not take my money. If I want access, I would need a friend to pay for me- but then I'm risking my friend's account if Claude figures it out.
I literally use(d) Claude for everything I do/did, except writing this article. I wasn't sure how I was banned from Claude and they won't tell me. All they can say is that I violated their Terms Of Service. Everything on their list is also illegal or immoral in real life, and what could a hacker have done with my account?
They Charged My Credit Card $5 at a Time
What's wild about this is that it all unfolds so slowly. It was a few days after that, I woke up to 86 charges on my American Express. All of the charges were $5, so it wouldn't kick off a fraud alert. But after the 86 charges, they made one charge for over $5,000 and that's when Amex finally noticed and stopped it.
Lessons Learned?
Chrome extensions can be very bad. If someone makes an extension and abandons it- like the developer dies- a hacker can come along and "claim" it as their own- like a Google business listing. Then the hacker updates the software and it's already on your machine.
The way this happened is that they/them/it stole my browser cookies. Meaning, if someone got hold of your browser cookies, they could just drop the cookies into their own Chrome cookie folder, and when they go to Facebook, they will automatically be logged in, just like you are.
That means my password was never leaked or guessed- and that makes a lot more sense. How could someone guess my password? Welp, the hacker never saw my password. Didn't need it!
But that's not all... My browser also has cookies that store my credit card information. So, like Facebook, nobody actually had to know my credit card number, they just needed to click a on "Google Pay" at checkout-- and my browser cookies just filled all of that out for them. The CSV? The hacker still doesn't know what that is. Google Pay uses asterisks in that field. They were able to use my credit card without having all of the info.
Google Will Never Leak Your Data, they say
Google will tell you that your credit card is 100% safe with them, and I believe it. But you know who your credit card is not safe with?
Your machine!
Before I figured out the Chrome Extension problem- I could not figure out how someone could have access to my machine. That should be impossible.
This is the bad side of AI. I am 100% certain that an automated AI agent was involved in this attack- in fact, there might not have been any human interaction at all. I can't tell. I don't want to write a book, but I have very specific reasons why I think this was an AI attack. I'll give you the most obvious one:
The 86 Fraudulent Charges Were All For Tokens
If you have a paid AI subscription, you pay for something called "tokens." Think of tokens as the currency that AI uses. When I woke up to all of those credit card charges, they were specifically used to buy AI tokens. Meaning, the AI was feeding itself with $5 charges. When it ran out of tokens, it said, "let me buy more in such a
way that Amex won't stop me".
Everything that was done was "virtual." Nobody purchased any food or assets with it. They didn't buy a computer or a skateboard. They just paid for AI food.
This is where it gets really crazy. The hacker was generating fake ads for fake AI slop. And as far as the tokens needed to run those ad campaigns- the AI was buying tokens for itself.
The AI that hacked me knew that more superior AI exists (Claude Fable). That's why the AI was paying for tokens-- it was using the tokens to access a smarter AI. I still can't wrap my head around it. But they used a cheap / free AI and that AI accessed Claude Fable and used Claude Fable do its dirty work. Hence, I was banned from Claude.
Imagine if you went to ChatGPT and chose their "dumber" model. But instead of giving you an answer that might be wrong, it goes and asks Grok, because it thinks that Grok is more knowledgeable for this particular task.
Yes, this sounds like science fiction and I wish it was.

Comments(20)