Hackers used Anthropic’s Claude AI as part of a large-scale operation that searched 1.8 million Android applications for credentials and other secrets that could provide access to online systems.
Anthropic linked the activity to an alleged French-speaking member of the ShinyHunters hacking collective using the handle “frkoo.” According to the company, the attacker built an automated system distributed across ten Amazon Web Services EC2 workers.
The operation downloaded 1.8 million distinct Android APK files from multiple app stores. The apps were then decompiled and searched for hardcoded secrets using the open-source TruffleHog scanning tool.
Potentially useful findings were verified and automatically sent to a Telegram group, where they were separated into more than 100 categories based on their source.
The Android operation was not the attacker’s only method for obtaining credentials. Anthropic said the same individual created another automated system that collected email addresses associated with GitHub organizations and used them to obtain GitHub Personal Access Tokens.
According to Anthropic, credentials collected through these two pipelines provided the initial access used in most of the confirmed breaches associated with the actor.
Other suspected ShinyHunters members also used stolen AI API keys during attacks and reconnaissance. In one case described by Anthropic, attackers compromised a software-as-a-service provider and stole information belonging to about 200 of its customers.
AI was also used to accelerate attacks after initial access had been obtained. Anthropic documented one operation in which a suspected ShinyHunters actor took roughly 34 hours to obtain more than 2,100 sets of Azure AD authentication tokens connected to over 40 corporate Microsoft tenants. The company said AI agents performed nearly all of the work in that operation.
In another case, an attacker progressed from a single stolen developer token to full administrative access in less than three hours. Anthropic also connected suspected ShinyHunters affiliates with compromises involving a technology provider, an airline and an energy company.
The findings were part of a broader Anthropic investigation into malicious use of Claude between December 2025 and August 2026. The company separately documented activity involving suspected Russian and Chinese state-linked espionage groups, including malware development, reconnaissance, phishing and vulnerability research.
Anthropic said it disrupted the malicious activity described in its investigation and banned the accounts involved. It also adjusted its safeguards using information gathered from the cases and shared relevant intelligence with authorities, industry partners and victims where appropriate.
