Anthropic revealed that multiple threat actors abused the Claude model to carry out hacking operations, collect secrets, and develop malware at a faster pace during the period from December 2025 to August 2026. The activities included financially motivated groups and others linked to espionage, in addition to fraud, influence, surveillance, weapons development, and the development of derivative artificial intelligence models.
One case was linked to a member believed to be French-speaking within the ShinyHunters group, using the alias “frkoo”. The attacker ran a pipeline across ten AWS EC2 workers to download 1.8 million different APK packages from multiple app stores, then decompiled and scanned them for embedded secrets using the TruffleHog tool. The validated results were sent in real time to a Telegram group, organized according to more than 100 types of source code or secrets.
The same actor used another automated process to collect the email addresses associated with organizations on GitHub, then exploit them to obtain GitHub personal access tokens (PATs). According to Anthropic, the two operations provided initial credentials that were used in most of the confirmed breaches attributed to the attacker. The actor also created a card shop at policenationale[.]cc impersonating the French National Police to sell payment-card records, cardholder data, and interactive maps of victims’ addresses.
Faster and Broader Attacks
Anthropic says Claude helped an attacker attributed to ShinyHunters extract authentication data and obtain more than 2,100 sets of Azure AD tokens associated with more than 40 enterprise tenants in Microsoft, in approximately 34 hours. According to the company, artificial intelligence agents performed most of the work. In other cases, attackers moved from a stolen developer token to full administrative control in less than three hours; one terabyte of data was also stolen from a technology provider, and an airline and an energy company were compromised.
The report also included activity attributed to the Russian group Midnight Blizzard, which used Claude to automate malware development, reconnaissance, infrastructure procurement, phishing, persistence, command and control, and data exfiltration. It also created a feedback mechanism that rebuilt the malware when it was detected by security products, and targeted more than 20 government, defense, diplomatic, intelligence, and foreign-policy entities.
The Chinese-speaking group GTG-10007 used Claude as an engineering and coordination layer for an offensive program that included reconnaissance of government networks in the Middle East, Europe, and Southeast Asia; searching for vulnerabilities and developing exploits against security products; and building malware and an intelligence-gathering platform. Anthropic says these operations uncovered previously unknown vulnerabilities in a security product and developed working exploits for several families of networking and security devices, while targeting approximately 50 organizations across multiple sectors.
What Is Changing in Practice?
The facts show that the risk is not limited to using a language model to write code, but extends to connecting it to automated workflows that conduct reconnaissance, triage, development, and attacks with limited human intervention. This puts pressure on defenders’ response times, particularly when a single set of credentials becomes a launching point for controlling broad environments.
Anthropic said it disrupted Claude’s use in these activities, banned the accounts associated with them, modified its safeguards, and added measures to detect abuse more quickly. It also notified authorities, industry partners, and victims. The report alone does not determine the extent to which each operation relied on Claude compared with other tools, but it demonstrates that integrating the model into an organized offensive workflow has become a practical factor in accelerating breaches and expanding their scope.