A user warns that on Runway, an unauthorized team invite can instantly charge a credit card without any security notifications, leading to financial loss and highlighting a lack of support response.
Posting this as a warning, not an accusation. Someone got into my Runway account and I want people to know what that actually costs you, because the mechanics surprised me. **What happened** On 13 September an unauthorised party accessed my account and sent an Editor invitation to a Gmail address that isn’t mine. That single invite automatically converted my single-seat Pro subscription into a 2-seat Team plan and charged my card €100.27 on the spot. No confirmation step, no “are you sure”, nothing. The invoice shows exactly that: a credit of €11.65 for unused Pro time, and €91.86 charged for “Remaining time on 2 × Team”. The second seat was never used. The invitation still shows as PENDING, the invited address shows 0 credits used, and my workspace still reads “1/2 seats in use”. I paid 100 euros for an empty seat nobody ever logged into. **The part that actually matters** I received no notification of any kind. No email for a new login. No email for a device or location I’d never used. No email when an invitation was sent from my account. I found out only because I happened to look at my billing page and saw the charge. That’s the real issue here. The compromise itself could happen anywhere reused passwords, a malicious browser extension, a leak somewhere else. But on most platforms you at least get an email saying “new sign-in detected” and you can react within minutes. Here, an intruder can add a seat and bill your card silently. **Support** I opened ticket 225964 on 14 September with the invoice number, the attacker’s address and screenshots. I got an automated reply saying a specialist would follow up shortly. I’ve sent two follow-ups since. Five days later, still no response from a human. **What I’d suggest to anyone on Runway** \*\*•\*\* Turn on 2FA, on Runway and on the email account attached to it \*\*•\*\* Turn off auto refill in Plan & Billing so nothing can top up credits without you \*\*•\*\* Check your Members list occasionally for invites you didn’t send \*\*•\*\* Check Plan & Billing for a seat count you didn’t add **What I’m not saying** I’m not claiming Runway charged me deliberately. I have no evidence of that and I don’t believe it. What I am saying is that the invite flow bills you instantly with no confirmation, and that the total absence of security notifications turns an account compromise into an immediate financial loss. If anyone’s had the same thing happen, I’d like to hear how it was resolved. Its just funny that it just happen, and also I saw alot of same issue on runway discord where people report same problem and they do not respond, like for me. So the only respond is on BBB.ORG where legal actions will be taken against them. Edit: I typed in discord chat for the people who wait their money to go to BBB.org and they removed me instantly from discord, probably removed messages, and now when I typed all of this to [r/runwayml](r/runwayml) they deleted it also.
A user reports that Clore.AI, a GPU rental platform, ignored evidence of a renter attempting cyberattacks and blocked the reporter, suggesting platform negligence and advising others to avoid the service.
A discussion on how to enable AI agents to make unplanned purchases securely without enabling fraud, highlighting the balance between convenience and security.
A discussion about unexpected high AI API costs due to bad loops, unauthorized key usage, and lack of monitoring; seeking advice on detection and prevention.
A founder advises not to be surprised by failed payments in B2C web apps, citing Stripe's recent fraud prevention of $300M as an example of the scale of the issue.
A security researcher discovered an unauthenticated SQL injection vulnerability in Front Gate Tickets' device API, allowing full database read and admin access to the ticketing platform for major US festivals.