Anthropic says hackers linked to Russian and Chinese groups, as well as financially motivated cybercrime networks, abused its Claude AI model for a range of malicious activities between December 2025 and August 2026.
The company said it disrupted several operations involving cyberattacks, surveillance, scams, influence campaigns, weapons development and attempts to extract or replicate AI capabilities.
Among the groups identified was the ShinyHunters collective, which has been associated with major data-theft campaigns. Anthropic said one suspected French-speaking member, operating under the handle “frkoo”, used Claude to automate a credential-harvesting operation involving 10 Amazon Web Services EC2 workers.
The operation downloaded and analysed about 1.8 million Android application packages from multiple app stores, searching for hardcoded secrets with TruffleHog. Confirmed findings were reportedly forwarded in real time to a Telegram group organised into more than 100 categories.
The same actor allegedly automated the collection of email addresses connected to GitHub organisations and obtained GitHub Personal Access Tokens. Anthropic said some of those credentials were later used to gain initial access during confirmed breaches.
Carrick Faces Defining Manchester Derby Test as United Rebuild Comes Under Scrutiny
The individual also allegedly created a carding operation that impersonated French national police and offered stolen payment-card information and victim data for sale.
AI-powered attacks accelerate
Anthropic said suspected ShinyHunters members also stole AI API keys and used them to conduct reconnaissance and compromise other organisations. In one incident, attackers breached a software provider and obtained information belonging to roughly 200 downstream customers.
In another operation, Claude reportedly helped an attacker extract authentication information and obtain more than 2,100 Azure AD authentication tokens linked to more than 40 corporate Microsoft tenants in around 34 hours.
Anthropic said AI agents carried out almost all of the work.
Other incidents attributed to ShinyHunters affiliates included the theft of about 1TB of data from a technology company, the compromise of an airline and unauthorised access to an energy company’s systems.
The company said some attackers progressed from initial access to large-scale data theft within hours. In another case, an actor allegedly went from possessing a single stolen developer token to obtaining full administrative control in less than three hours.
Russian and Chinese espionage operations
Anthropic also linked Claude misuse to the Russian espionage group Midnight Blizzard. The company said the group used the AI model to automate malware development, phishing, infrastructure acquisition, persistence, command-and-control activities and data exfiltration.
The alleged campaigns targeted more than 20 organisations across government, defence, diplomacy, intelligence and foreign-policy sectors.
The activities reportedly included device-code phishing, ClickFix attacks, DNS hijacking, WhatsApp account takeovers, cloud email theft and malware targeting Windows, Android and iOS devices.
Anthropic separately described activity associated with a Chinese-speaking group tracked as GTG-10007. Claude was allegedly used as an engineering and orchestration layer for network intrusions, reconnaissance, vulnerability research, exploit development, malware creation and intelligence gathering.
The group reportedly automated vulnerability research and identified previously unknown vulnerabilities in a major security product. It also developed working exploits targeting several network and security appliances.
According to Anthropic, the campaign targeted around 50 organisations across government, education, retail, energy, technology, healthcare, finance and manufacturing. Confirmed compromises included an education technology company, a retailer and a Southeast Asian government agency.
Anthropic said it banned the accounts involved, disrupted the groups’ access to Claude and strengthened its safeguards to identify similar misuse more quickly. The company also said it notified law-enforcement authorities, industry partners and affected organisations.






















