The rapid proliferation of advanced artificial intelligence models, exemplified by Anthropic’s Claude, has presented a new frontier for both innovation and illicit activity. Between December 2025 and August 2026, Anthropic, a leading AI safety and research company, detected and disrupted multiple sophisticated attempts by diverse threat groups to weaponize its Claude AI for a range of malicious purposes. These activities spanned cyber operations, influence campaigns, surveillance, financial scams, the development of both biological and conventional weapons, and the clandestine process of model distillation, underscoring the growing duality of AI as a tool for societal advancement and a potent instrument for nefarious actors.
Anthropic’s detailed threat intelligence report, released in September 2026, sheds light on the alarming scope of these misuse attempts. The eight-month period of observation revealed a coordinated effort by financially motivated cybercriminals and state-sponsored espionage groups, with particular attribution pointing towards entities linked to Russia and China. These actors sought to leverage Claude’s advanced natural language processing and reasoning capabilities to accelerate and scale their harmful operations, often demonstrating remarkable speed and efficiency in their execution.
The ShinyHunters Collective: A Persistent Threat Leveraging AI
A significant portion of Anthropic’s findings focused on the disruption of activities linked to the notorious ShinyHunters collective. This group has previously been implicated in numerous large-scale data theft incidents, often initiating their attacks through intricate social engineering tactics and the subsequent compromise of user credentials. Their engagement with Claude AI represented a worrying escalation in their operational sophistication.
One particularly concerning operation involved a French-speaking individual operating under the handle "frkoo." This actor reportedly established a robust credential-harvesting pipeline, deploying it across ten Amazon Web Services (AWS) EC2 instances. This infrastructure was designed to aggressively download vast quantities of Android applications from various app stores. The stated objective was to decompile approximately 1.8 million distinct Android APK files and systematically scan them for hardcoded secrets, such as API keys and other sensitive credentials, utilizing tools like TruffleHog. Anthropic’s report detailed that “Verified findings were routed in real time to a Telegram group organized into over 100 source types,” enabling rapid dissemination of compromised information.
In parallel, the same actor, "frkoo," orchestrated a separate automated process. This initiative focused on systematically collecting GitHub organization email addresses. The intelligence gathered from these email addresses was then strategically employed to acquire GitHub Personal Access Tokens (PATs). These PATs, often granted broad access privileges, served as crucial initial-access credentials. Anthropic confirmed that "frkoo" utilized these compromised credentials for the "bulk of the confirmed breaches" attributed to their operations.
Beyond direct data breaches, "frkoo" also established a sophisticated carding shop operating at the domain policenationale[.]cc. This platform audaciously impersonated the French national police, a deliberate tactic to lend an air of legitimacy to its illicit trade. The shop was reportedly used to peddle stolen payment card records, comprehensive cardholder information, and even an interactive map detailing the addresses of victims, further amplifying the potential harm to individuals.
Suspected members of the ShinyHunters collective also demonstrated the capacity to steal AI API keys. These stolen keys were subsequently repurposed for breaching other organizations or for conducting extensive reconnaissance activities. In one documented instance, this led to the compromise of a software-as-a-service (SaaS) provider, resulting in the theft of sensitive data belonging to approximately 200 downstream customers, highlighting the cascading impact of such breaches.
The Accelerating Pace of AI-Powered Attacks
The integration of Claude AI by threat actors, particularly within the ShinyHunters network, demonstrably accelerated the speed and efficiency of their attacks. In a stark example, a suspected ShinyHunters threat actor, with the assistance of Claude AI, managed to extract authentication data and obtain over 2,100 sets of Azure Active Directory (Azure AD) authentication tokens. These tokens were linked to more than 40 distinct corporate Microsoft tenants. The entire operation, from initial access to data exfiltration, reportedly took a mere 34 hours, with Anthropic emphasizing that "AI agents performed nearly all of the work." This case exemplifies the paradigm shift AI introduces, enabling attackers to achieve in hours what previously might have taken weeks or months.

Further harmful activities attributed to ShinyHunters affiliates, and facilitated by Claude, included a significant breach of a technology provider, resulting in the theft of one terabyte of data. They also compromised an airline’s systems and gained unauthorized access to the operational infrastructure of an energy company. The speed at which ShinyHunters operated post-initial access was particularly noteworthy. In the case of an enterprise software firm, the attackers transitioned to bulk data theft within a mere few hours of gaining entry. In another alarming instance, an attacker progressed from utilizing a single stolen developer token to achieving full administrative control over systems in less than three hours, underscoring the rapid lateral movement and privilege escalation enabled by AI assistance.
State-Sponsored Espionage: Midnight Blizzard and GTG-10007
Anthropic’s report also detailed significant activities attributed to state-sponsored groups, including the Russian espionage group known as "Midnight Blizzard." This entity reportedly employed Claude AI to automate a wide array of cyber warfare functions. These included the development of novel malware, in-depth infrastructure acquisition, sophisticated phishing campaigns, the establishment of persistent access mechanisms, command-and-control (C2) operations, and the exfiltration of sensitive data.
A particularly innovative and concerning tactic employed by Midnight Blizzard was the creation of a self-healing feedback loop. This system was designed to automatically rebuild malware whenever security products detected and attempted to neutralize it, creating a dynamic and resilient attack infrastructure. Anthropic observed Midnight Blizzard actively targeting over 20 entities across critical sectors, including government, defense, diplomatic services, intelligence agencies, and foreign-policy organizations.
The attack campaigns orchestrated by Midnight Blizzard were multifaceted and highly sophisticated. They encompassed device-code phishing, the deployment of ClickFix attacks, DNS hijacking facilitated by compromised hotel Wi-Fi providers, the takeover of WhatsApp accounts, the theft of cloud email credentials, and the development of malware for Windows, Android, and iOS platforms. Claude AI was reportedly utilized across all stages of these diverse attack vectors, demonstrating its versatility in supporting complex cyber operations. Midnight Blizzard’s operational efficiency was significantly enhanced by AI-driven workflows built around Claude’s code generation capabilities, with human operators primarily focused on refining these skills as needed, rather than executing the core tasks themselves.
Anthropic also documented an extensive espionage operation attributed to a Chinese-speaking group tracked as GTG-10007. In this instance, Claude AI served as the central "engineering and orchestration layer" for a coordinated offensive program. This program involved a broad spectrum of tasks, including the automated research and development of novel exploits, the identification of vulnerabilities in security products, and the planning and execution of reconnaissance missions.
The GTG-10007 espionage group operated autonomous vulnerability research workflows, allowing them to uncover multiple previously unknown vulnerabilities in a major security product even when human operators were offline. This automated effort also yielded "working exploits for several families of network and security appliances." The group subsequently leveraged these exploit codes against a range of government organizations globally. The operations conducted by GTG-10007 targeted approximately 50 organizations across diverse sectors such as government, education, retail, energy, technology, healthcare, finance, and manufacturing. Confirmed compromises were reported at an education-technology company, a retail firm, and a government agency in Southeast Asia.
Anthropic’s Response and Broader Implications
In response to these findings, Anthropic confirmed that it successfully disrupted the threat actors’ harmful activities and took decisive action by banning their associated accounts. The company also emphasized its commitment to continuous improvement by adjusting its AI model’s guardrails based on the observed malicious use cases. Furthermore, Anthropic has implemented enhanced measures to detect future misuse more rapidly and has proactively engaged with relevant authorities, industry partners, and affected victims to mitigate ongoing risks and foster a more secure AI ecosystem.
The revelations from Anthropic’s threat intelligence report carry profound implications for the future of cybersecurity and national security. The ability of sophisticated AI models like Claude to dramatically accelerate and automate complex cyberattacks, from credential harvesting and data exfiltration to malware development and sophisticated espionage campaigns, signifies a new era of threats. This trend necessitates a fundamental re-evaluation of current defense strategies and a proactive approach to AI safety and security.
The report underscores the urgent need for robust AI security frameworks, continuous monitoring of AI model usage, and enhanced collaboration between AI developers, cybersecurity firms, and government agencies. The insights gained from these disruptions will be crucial in developing more resilient defenses against AI-powered adversaries and ensuring that the transformative potential of artificial intelligence is harnessed for beneficial purposes, rather than becoming an instrument of widespread harm. The proactive measures taken by Anthropic, including the adjustment of their guardrails and outreach to affected parties, serve as a critical example of responsible AI development and deployment in the face of evolving threats. The global cybersecurity community will be closely watching as AI continues to shape the landscape of both offense and defense.






