Zoli Rutter replied "no" to a £90.90 Metro Bank charge; the bank treated it as a per transaction veto, and £14,000 (about $18,000) of follow on fraud walked out.
On 19 June, a £90.90 (about $115) charge appeared on Zoli Rutter's debit card. The Sussex businessman replied with one word: "no." Metro Bank blocked that single transaction. It did not freeze his card. Over the next 24 hours, subsequent charges of £90 to £200 (about $115 to $255) cleared his account. By the time Metro Bank finally froze the card the next day, £14,244, about $18,100 at current exchange rates, had been taken.
The fraudsters had used the card on file for Rutter's Anthropic account, the US company behind the AI chatbot Claude, to buy Claude credits in rapid succession. Rutter, who pays about £15 a month (about $19) for a Claude subscription to track and analyze his business invoices, only learned the scale of the loss when his direct debits started bouncing.
The case turns on a question almost no consumer thinks to ask: when a bank texts you about a suspicious charge and you reply "no," what exactly are you rejecting? Metro Bank's text-based alert is built around a per-transaction veto. A "no" reply blocks the individual charge. It does not, by default, freeze the underlying card. That design exists for a reason. A single suspicious charge is often a wrong purchase or a duplicate, and locking the card on every "no" reply would create more customer harm than it prevents.
The design has a hole. Once a customer has explicitly opted out of a charge, any follow-on transaction at the same merchant, in the same velocity pattern, is, by definition, not the customer. Metro Bank's velocity and merchant-category rules did not catch the wave of £90 to £200 charges from Anthropic's payment processor in the 24 hours after Rutter's "no." That gap is what the case exposes, and what the aggregator headlines skip.
After Guardian Money contacted the bank, Metro Bank temporarily refunded Rutter while pursuing a chargeback from Anthropic. A spokesperson said the case involved "the complex nature of the fraud, regretfully some payments were processed" against a debit card the customer had previously used to make "genuine payments" to Anthropic. The bank described it as "a concerning case involving a third party that the customer had made previous genuine payments [to]."
That defense is the strongest available to the bank: a recurring-debit relationship with a real merchant, a per-transaction alert system that worked as designed, and a fraud pattern that mimicked the customer's normal spend. It is also the falsifier. The customer had explicitly told the bank the charge was not his. The bank's own rules then let the next charges through.
Rutter is not the first. In May 2026, a US Claude user told Guardian Money that gift-card fraudsters had used his financial details to drain his account. Similar stories have surfaced on Reddit. The shared shape: a customer's payment details, stored by Anthropic for a small recurring subscription, become the entry point for a fraudster who tops up Claude credits at high velocity.
The risks come in two flavors, and they should not be confused. The first is a payment-fraud pattern: a stored debit card on a chatbot subscription becomes a target for credit-top-up fraud. The second is a privacy pattern. The same week the Metro Bank case became public, it was revealed that some users' Claude conversations were publicly available online, a separate exposure that turns stored payment details into a question of who can read what the customer typed.
The same week, the Financial Conduct Authority (FCA), the City regulator, gave Anthropic access to its hi-tech AI sandbox "to help speed up their development work." Guardian Money described the move as the FCA "appearing to endorse" Claude. A sandbox placement is not a product endorsement, but it does put the regulator's posture toward the underlying product on the table at the same moment its payment-fraud pattern is being reported on.
Rutter's case is now a model every UK bank customer can borrow. The next time your bank texts about a suspicious charge, three questions are worth putting in writing to the fraud team, not the chatbot:
A "no" reply is the start of a conversation with your bank, not the end of one. Rutter's £14,244 (about $18,100) is the price of treating it as the end.