Threat Groups Used Anthropic Claude AI to Target Millions of Apps and Systems
AI

Threat Groups Used Anthropic Claude AI to Target Millions of Apps and Systems

TechNews Editorial
TechNews EditorialSep 14, 2026 · 2 min read
Share

Anthropic stated that multiple threat groups tried to abuse its Claude AI model for malicious purposes. The company recorded artificial intelligence misuse between December 2025 and August 2026. This misuse covered cyber and influence operations, surveillance, scams, biological and conventional weapons development, and model distillation.

Anthropic disrupted several activities linked to the ShinyHunters collective during this eight-month period. An alleged French-speaking member of the group using the handle frkoo distributed a credential-harvesting pipeline across ten AWS EC2 workers. This setup downloaded and scanned 1.8 million Android APKs for secrets.

Anthropic explains that this pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog. Verified findings were routed in real time to a Telegram group organized into over 100 source types.

The actor also collected GitHub organization email addresses to obtain GitHub Personal Access Tokens. These credentials powered the bulk of confirmed breaches associated with the hacker. Furthermore, frkoo set up a carding shop at policenationale.cc that impersonated the French national police to sell stolen payment-card records.

Suspected ShinyHunters members stole AI API keys to breach other organizations and conduct reconnaissance. In one instance, they breached a SaaS provider and stole data belonging to about 200 downstream customers. AI agents performed nearly all of the work to extract authentication data and get more than 2,100 sets of Azure AD authentication tokens.

Additional harmful activity linked to ShinyHunters and Claude involved breaching a technology provider and stealing 1TB of data, compromising an airline, and accessing systems of an energy company. The hackers moved quickly after gaining initial access, reaching bulk data theft in just a few hours in some cases.

Anthropic highlighted activity from the Russian espionage group Midnight Blizzard. This group used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command-and-control operations, and data exfiltration. The threat actor set up a feedback loop that rebuilt malware whenever security products detected it.

Midnight Blizzard targeted over 20 government, defense, diplomatic, intelligence, and foreign-policy entities. The campaigns featured device-code phishing, ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeovers, cloud-email theft, and multi-platform malware. The group automated its operations through AI-driven workflows built around Claude Code skills.

Anthropic described an espionage operation attributed to a Chinese-speaking group tracked as GTG-10007. This group used Claude as the engineering and orchestration layer of a coordinated offensive program. GTG-10007 operated autonomous vulnerability-research workflows while human operators were away, uncovering multiple previously unknown vulnerabilities in a major security product.

The automated effort also delivered working exploits for several families of network and security appliances. The actor leveraged the exploit code against several government organizations around the globe. Overall, the group targeted around 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing.

Anthropic disrupted the actors' use of Claude for harmful activities and banned their accounts. The company adjusted its guardrails, added measures to detect future misuse faster, and contacted authorities, industry partners, and victims.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Related Stories