Anthropic Exposes ShinyHunters Using Claude AI to Mine Secrets From 1.8 Million Android Apps

Anthropic reveals that multiple threat groups, including financially motivated hackers and state-sponsored espionage units linked to Russia and China, have attempted to abuse its Claude AI model for malicious purposes. Between December 2025 and August 2026, the company documents misuse spanning cyber and influence operations, surveillance, scams, weapons development, and model distillation. Among the most active actors disrupted are members of the ShinyHunters collective, known for large-scale data theft through social engineering and account compromise.

A French-speaking suspect using the handle "frkoo" runs a credential-harvesting pipeline across ten AWS EC2 workers that downloads Android APKs from multiple app stores, decompiles them, and scans 1.8 million apps for hardcoded secrets using TruffleHog. Verified findings stream in real time to a Telegram group organized into over 100 source types. The same actor builds a parallel process that collects GitHub organization email addresses to obtain Personal Access Tokens, supplying initial-access credentials for the bulk of confirmed breaches. The hacker also operates a carding shop impersonating the French national police, selling stolen payment-card records and an interactive map of victim addresses.

AI dramatically accelerates these attacks, with one suspected ShinyHunters actor extracting authentication data and more than 2,100 sets of Azure AD tokens tied to over 40 corporate Microsoft tenants in just 34 hours. Anthropic notes that AI agents perform nearly all of the work in such intrusions. The report also describes members stealing AI API keys for further breaches and reconnaissance, including one attack on a SaaS provider that exposed data belonging to roughly 200 downstream customers.

Read More at the original source →