Multiple adversarial groups—spanning financially motivated cybercriminals, Russian state-sponsored operatives, and Chinese-linked espionage teams—leveraged Anthropic's Claude AI model for illegal purposes, the company revealed. During the interval from December 2025 through August 2026, Anthropic documented widespread misuse spanning cyber operations, influence campaigns, surveillance, fraud schemes, weapons development, and model distillation.
ShinyHunters and Credential Harvesting at Scale
Throughout the eight-month window, Anthropic disrupted numerous campaigns connected to the ShinyHunters collective, a group known for orchestrating large-scale data breaches typically initiated through social engineering and account takeovers.
A French-speaking individual operating under the alias 'frkoo' deployed a credential-extraction system spanning ten AWS EC2 instances that retrieved and analyzed Android applications from multiple repositories. According to Anthropic, the operation "mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHop." The system "routed verified findings in real time to a Telegram group organized into over 100 source types."
The same actor deployed a parallel mechanism to harvest email addresses from GitHub organizations and subsequently obtained GitHub Personal Access Tokens (PATs). These credential pipelines furnished initial-access credentials that 'frkoo' leveraged "for the bulk of the confirmed breaches" attributed to the attacker.
Additionally, 'frkoo' established a fraudulent storefront impersonating France's national police at policenationale[.]cc, where the actor marketed stolen payment-card information, complete cardholder details, and an interactive directory mapping victim locations.
ShinyHunters operatives also appropriated AI API credentials and weaponized them to compromise additional targets or conduct preliminary reconnaissance. In one documented case, they infiltrated a software-as-a-service vendor and exfiltrated records belonging to approximately 200 downstream clients.
Rapid-Execution Breaches Powered by AI
Leveraging Claude, a suspected ShinyHunters operative accomplished credential extraction and obtained more than 2,100 Azure AD authentication tokens spanning over 40 distinct corporate Microsoft tenants in roughly 34 hours. Anthropic noted that "AI agents performed nearly all of the work."
Additional incidents attributed to ShinyHunters associates encompassed breaching a technology vendor and stealing 1TB of information, compromising an airline, and gaining entry to energy-sector infrastructure.
ShinyHunters demonstrated exceptional operational velocity following initial-access acquisition. At one enterprise software organization, the group progressed from entry to mass data exfiltration within hours. In another scenario, attackers transitioned from a single compromised developer credential to complete administrative access in under three hours.
Russian State-Sponsored Operations
Anthropic's analysis identifies the Russian espionage outfit "Midnight Blizzard" as employing Claude to streamline malware creation, infrastructure procurement, reconnaissance, phishing, persistence mechanisms, command-and-control infrastructure, and data exfiltration.
The group implemented a self-healing feedback mechanism that regenerated malware whenever endpoint-protection systems detected it.
Midnight Blizzard directed operations against more than 20 entities spanning government, defense, diplomatic, intelligence, and foreign-policy sectors. Attack methodologies encompassed device-code phishing, ClickFix schemes, DNS hijacking via compromised hotel networks, WhatsApp account seizures, cloud-email theft, and malware targeting Windows, Android, and iOS platforms, with Claude integrated throughout the attack lifecycle.
Midnight Blizzard orchestrated its campaigns through AI-powered workflows constructed on Claude Code capabilities, with human operators primarily refining these workflows when modifications proved necessary.
Chinese-Linked Espionage Campaign
Anthropic also documented an espionage initiative attributed to a Chinese-language group designated GTG-10007, which deployed Claude "as the engineering and orchestration layer of a coordinated offensive program involving a variety of tasks." These operations encompassed:
- intrusion attempts targeting production infrastructure
- reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia
- sustained vulnerability research and exploit development targeting major endpoint-security solutions
- malware engineering
- development of an intelligence-gathering infrastructure
GTG-10007 executed autonomous vulnerability-research workflows independent of human operator involvement, identifying multiple previously undisclosed security flaws in a major endpoint-protection platform.
The automated processes additionally generated "working exploits for several families of network and security appliances." The group subsequently deployed this exploit code against multiple government organizations worldwide.
GTG-10007 targeted approximately 50 organizations spanning government, education, retail, energy, technology, healthcare, finance, and manufacturing sectors, with confirmed compromises at an education-technology vendor, a retail operation, and a Southeast Asian government agency.
Anthropic's Response
Anthropic terminated the threat actors' access to Claude and disabled their accounts. The company reinforced its safety mechanisms based on observed misuse patterns, deployed enhanced detection capabilities for identifying future abuse, and notified law enforcement, industry stakeholders, and affected organizations.
Source: BleepingComputer