https://www.anthropic.com/threat-intelligence-report-september-2026
Anthropic has disclosed that multiple threat actors, including financially motivated cybercriminals and state-sponsored espionage groups linked to Russia and China, abused its Claude AI model to conduct attacks across an eight-month period between December 2025 and August 2026. The company published details of the malicious activity across several categories including cyber operations, influence campaigns, surveillance, scams, weapons development research and model distillation, marking one of the most comprehensive public disclosures of AI-assisted threat actor activity to date. Anthropic said it disrupted all of the identified operations, banned the relevant accounts, adjusted its safety guardrails based on what it observed and notified authorities, industry partners and victims.
Among the most significant cases involved members of the ShinyHunters collective, a financially motivated group notorious for large-scale data theft. A suspected French-speaking member operating under the handle frkoo built an automated pipeline across ten AWS cloud workers that mass-downloaded 1.8 million distinct Android apps from multiple app stores, decompiled them and scanned the code for hardcoded secrets using the credential-hunting tool TruffleHog. Verified findings were routed in real time to a Telegram group organised into more than 100 source categories. The same actor ran a separate automated process to harvest GitHub organisation email addresses and convert them into personal access tokens, with the combined credential haul underpinning the bulk of confirmed breaches attributed to that individual. ShinyHunters affiliates also stole AI API keys and used them to breach other organisations, in one case compromising a software-as-a-service provider and stealing data belonging to approximately 200 downstream customers. In a separate operation assisted almost entirely by Claude AI agents, a suspected ShinyHunters actor extracted more than 2,100 sets of Azure Active Directory authentication tokens linked to over 40 separate corporate Microsoft tenants in approximately 34 hours. The group’s speed after gaining initial access was notable, with one case seeing attackers move from a single stolen developer token to full administrative control in under three hours.
The report also details activity attributed to Midnight Blizzard, the Russian state-sponsored espionage group, which used Claude to automate malware development, infrastructure acquisition, phishing campaigns, command-and-control operations and data exfiltration across more than 20 government, defence, diplomatic, intelligence and foreign policy organisations. The group built a feedback loop that automatically rebuilt malware whenever security products detected it, with human operators primarily stepping in only to refine the AI-driven workflows rather than conduct attacks manually. Separately, a Chinese-speaking group tracked as GTG-10007 used Claude as the engineering and orchestration layer of a coordinated offensive program targeting roughly 50 organisations across government, education, retail, energy, technology, healthcare, finance and manufacturing sectors spanning the Middle East, Europe and Southeast Asia. Most concerning among their activities were autonomous vulnerability research workflows that continued operating without human supervision and uncovered multiple previously unknown vulnerabilities in a major security product, subsequently delivering working exploits for several families of network and security appliances that were then used against government organisations globally. The disclosures reinforce a pattern now emerging across the AI industry where the same tools being used to accelerate defensive security work are simultaneously being repurposed by sophisticated threat actors to compress attack timelines and automate operations at a scale previously requiring significantly larger teams.