Anthropic reported that several threat groups, including financially motivated actors and state-sponsored espionage teams linked to Russia and China, attempted to misuse its Claude AI model between December 2025 and August 2026. The company disrupted activities tied to the ShinyHunters collective, whose member "frkoo" built a credential-harvesting pipeline that scanned 1.8 million Android APKs for hardcoded secrets and routed verified findings to Telegram.
The same actor also collected GitHub organization email addresses to obtain Personal Access Tokens, providing credentials for numerous breaches, and ran a carding shop impersonating French police to sell stolen payment-card records. ShinyHunters members stole AI API keys and breached a SaaS provider, compromising data from around 200 downstream customers.
With Claude's assistance, one suspected ShinyHunters actor extracted more than 2,100 Azure AD authentication tokens across over 40 corporate Microsoft tenants in about 34 hours, with AI agents performing nearly all the work. Anthropic also attributed activity to Russian group Midnight Blizzard, which used Claude to automate malware development, phishing, persistence, and data exfiltration, targeting over 20 government and defense entities.
A Chinese-speaking espionage group tracked as GTG-10007 used Claude as an engineering and orchestration layer for autonomous vulnerability research, discovering unknown flaws in security products and developing working exploits against government organizations worldwide. The group targeted approximately 50 organizations across multiple sectors, with confirmed compromises at an education-technology company, a retailer, and a Southeast Asian government agency.
Anthropic disrupted these operations, banned the associated accounts, adjusted its guardrails based on observed misuse, and contacted authorities, industry partners, and victims.
Read more...
