Anthropic has published new findings on hackers who tried to turn its own AI tool into a weapon. The report covers cases of Claude AI abuse from December 2025 to August 2026. One case stands far above the rest, because a single actor fed 1.8 million Android apps into a pipeline built to hunt for hidden keys.
How one Claude AI abuse case scanned 1.8 million apps
A French-speaking member of the ShinyHunters group, known by the handle “frkoo”, spread a credential-harvesting pipeline across ten cloud servers. The setup pulled 1.8 million Android APK files from several app stores, unpacked every one of them, and combed the code for hardcoded secrets. Those secrets work like spare keys.
APK files are the install packages behind every Android app. Anyone can download one and pull it apart. Developers often leave material inside by mistake, so API keys, access tokens and database passwords end up baked into the code.
Verified hits flowed straight into a Telegram group. The hacker sorted them into more than 100 source types, which made the whole haul searchable. Finding such mistakes by hand takes days for a handful of apps. So this Claude AI abuse case turned slow research into a live feed of working logins.
A second pipeline collected GitHub company email addresses, then used them to grab Personal Access Tokens. Together, the two systems opened the door to most of his confirmed breaches. He also ran a carding shop that posed as the French national police, selling stolen card records and a clickable map of victim addresses.
Attacks that finished in hours, not weeks
Speed defines every Claude AI abuse case in this report. One suspected ShinyHunters actor worked for roughly 34 hours and pulled more than 2,100 sets of Azure AD login tokens from over 40 corporate Microsoft accounts. Anthropic states that AI agents did nearly all of the work.
A single stolen developer token became full admin access in under three hours, and another intrusion moved faster still. At one business software firm, attackers reached bulk data theft within hours of getting in. Security teams rarely notice, escalate and respond on that clock.
Other activity by the same crew includes 1TB stolen from a tech provider, a compromised airline and access to an energy company’s systems. Suspected members also stole AI API keys from victims and reused them against other firms. One breached software provider exposed data on roughly 200 downstream customers.
State-backed groups ran the same playbook
Money was not the only motive at work here. Not every case of Claude AI abuse came from a criminal outfit, because the company also tracked two spy operations, one Russian and one Chinese-speaking. Both treated the model as working machinery rather than a novelty.
Midnight Blizzard and the hotel Wi-Fi trick
This strand of Claude AI abuse ran across the whole attack chain. The Russian group Midnight Blizzard automated malware building, research, server rental, phishing and data theft, then aimed the result at more than 20 government, defense and diplomatic bodies. It even built a loop that rebuilt its malware whenever a security product caught it.
Device-code phishing, ClickFix lures, WhatsApp account takeovers and cloud email theft all featured in its campaigns. One method matters directly to travelers. The group hijacked DNS traffic through hacked hotel Wi-Fi providers, a trick that quietly sends your browser to servers the attacker controls even when the web address in the bar looks correct. A VPN blunts that trick, because it encrypts your traffic and moves name lookups away from the local network.
A Chinese-speaking group that worked alone
In this Claude AI abuse case, a group tracked as GTG-10007 used the model as its engineering layer. Its tasks ran from break-in attempts on live systems to scouting government networks across the Middle East, Europe and Southeast Asia. The group also hunted for flaws in major endpoint-security products and built its own intelligence platform.
Some of that bug hunting ran on its own while the operators slept. Those unattended workflows found several unknown flaws in a major security product. They also produced working exploits for network and security appliances, which the group then fired at government bodies around the world. Around 50 targets came under attack in all, across government, education, retail, energy, healthcare and finance.
Why Claude AI abuse matters for everyday privacy
Few readers will ever land on a spy team’s target list. The logins harvested in these operations still fuel breaches at ordinary companies, and those firms hold your email, your card details and your order history. So the Claude AI abuse described here feeds the leaks that surface months later.
Anthropic banned the accounts involved and tightened its guardrails. It also added faster detection and warned authorities, partners and victims. Those steps arrived after the fact, though. Every major AI provider now sits under the same pressure.
Personal defenses have not changed much, but the margin for error has shrunk. Unique passwords and a password manager strip the value from one leaked login. Two-factor authentication blocks most token-replay attempts. Encrypting your connection on public Wi-Fi closes the hotel route above.
Final Thoughts
The pattern across all three groups has little to do with clever prompting. These actors automated the dull parts of a break-in, then let machines handle volumes no human crew could match. Claude AI abuse in this report scales up old tricks rather than inventing new ones.
Companies face a shrinking window between the first stolen token and full compromise. They will need faster responses, tighter audits of app exposure and sharper key rotation. For everyone else, the sensible answer stays dull and effective. Strong logins, care on public networks and the assumption that leaked data circulates cover most of the risk.