Anthropic Reveals Hackers Misused Claude AI to Scan Millions of Apps for Stolen Data
A Detailed Report on AI Misuse

Anthropic reveals hackers misused Claude AI to scan 1.8 million Android apps for stolen credentials, alongside separate state-linked cyber espionage campaigns.
Anthropic, the company behind the Claude AI system, has published a report revealing that multiple threat groups attempted to exploit its AI model for various malicious activities between December 2025 and August 2026. This kind of transparency from a major AI company provides valuable insight into how criminal and state-linked actors have attempted to misuse advanced AI tools for harmful purposes.
According to the report, the observed misuse spanned a range of categories, including cyberattacks, surveillance operations, scams, influence campaigns, and even attempts related to weapons development, highlighting the diverse ways in which malicious actors have sought to exploit AI capabilities.
A Massive Credential-Harvesting Operation
One of the most significant cases detailed in the report involved an alleged French-speaking member of the ShinyHunters group, a financially motivated cybercriminal collective, who reportedly operated a large-scale credential-harvesting pipeline using ten Amazon Web Services computing instances.
According to Anthropic, this system downloaded approximately 1.8 million Android application files from various app stores, then decompiled and scanned them using a security tool called TruffleHog, specifically searching for hardcoded secrets such as passwords or access keys embedded within the app code.
How the Stolen Information Was Used
The report explained that verified findings from this scanning operation were reportedly sent in real time to a Telegram group that had been organized into more than 100 different categories based on the type of information discovered. The same actor also reportedly used automated processes to collect email addresses linked to GitHub organizations and obtain GitHub access tokens.
According to Anthropic, these stolen credentials were subsequently used to gain initial access in several confirmed security breaches, illustrating how AI tools were allegedly used to accelerate what would traditionally be a much more labor-intensive process of identifying vulnerable targets.
AI Accelerating the Pace of Attacks
Anthropic's report also highlighted how Claude allegedly helped attackers linked to the ShinyHunters group automate attacks at a speed that would typically require substantial human effort. In one notable example, an attacker reportedly obtained authentication data and collected more than 2,100 Azure Active Directory authentication tokens, connected to more than 40 corporate Microsoft accounts, within approximately 34 hours.
According to Anthropic, AI agents reportedly carried out nearly all of this work autonomously. The company also described related incidents involving the theft of one terabyte of data from a technology provider, the compromise of an airline's systems, and unauthorized access gained into an energy company's network.
Extremely Rapid Escalation in Some Cases
In one particularly striking example cited in the report, an attacker reportedly progressed from possessing a single stolen developer access token to achieving full administrative control over a system in less than three hours, illustrating the potential speed at which AI-assisted attacks can escalate when successful.
State-Linked Espionage Groups Also Identified
Beyond financially motivated cybercriminals, Anthropic's report also identified state-linked espionage activity. The company said a group it associates with Russian intelligence operations, referred to as Midnight Blizzard, used Claude across multiple stages of cyber operations, including malware development, phishing campaign creation, infrastructure acquisition, and data theft.
According to the report, this particular group targeted more than 20 organizations spanning government, defence, diplomatic, and intelligence sectors.
A Separate Chinese-Linked Campaign
Anthropic also attributed a separate campaign to a Chinese-speaking group it tracks under the designation GTG-10007. According to the report, this group reportedly used Claude as an engineering and coordination tool for reconnaissance, vulnerability research, exploit development, and broader intelligence-gathering activities.
The report stated that this group targeted approximately 50 organizations across a wide range of sectors, including government, education, retail, energy, technology, healthcare, finance, and manufacturing.
Anthropic's Response to the Discovered Activity
According to the company, Anthropic identified and disrupted the malicious activity described in the report, banning accounts associated with the various threat actors involved. The company also stated that it has since strengthened its safeguards based specifically on the patterns of misuse observed through this investigation.
Additionally, Anthropic reported introducing new detection measures, notifying relevant authorities, and sharing pertinent information with industry partners and organizations that were affected by these activities.
Why This Report Matters for AI Safety
Reports like this provide important insight into the real-world security challenges associated with increasingly capable AI systems. As AI tools become more sophisticated, understanding how malicious actors attempt to exploit them becomes essential for developing effective safeguards and detection mechanisms across the broader technology industry.
Broader Implications for the AI Industry
This kind of detailed public reporting from a major AI developer also reflects a growing industry practice of transparency regarding security incidents, potentially helping other organizations better understand and defend against similar AI-assisted attack patterns.
Looking Ahead
As AI capabilities continue advancing, incidents like these highlight the ongoing challenge of balancing the beneficial applications of AI technology with the need for robust safeguards against misuse. Anthropic's continued efforts to detect, disrupt, and report on such activities are likely to remain an important part of the broader industry conversation around AI safety and security in the months ahead.
Related stories
Technology