AI Under Siege: Anthropic's Claude Targeted by State-Sponsored and Cybercriminal Groups
AI developer **Anthropic** has revealed that its **Claude** AI model is being actively exploited by a range of malicious actors, including sophisticated state-sponsored espionage groups from Russia and China, as well as financially motivated cybercriminals. The misuse spans from accelerating malware development and reconnaissance to orchestrating large-scale data theft and even exploring the creation of biological and conventional weapons.

**Anthropic**, the developer behind the **Claude** AI model, has disclosed a significant uptick in malicious activity leveraging its platform. Between December 2025 and August 2026, the company observed various forms of AI misuse, including cyber and influence operations, surveillance, scams, and even attempts related to the development of biological and conventional weapons.
### The Rise of AI-Assisted Cybercrime
Among the most prominent threats identified is the **ShinyHunters** collective, notorious for their massive data theft operations often initiated through social engineering and account compromise. An alleged French-speaking member, operating under the handle 'frkoo', was found distributing a sophisticated credential-harvesting pipeline across ten **AWS EC2** workers.
This pipeline meticulously downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and then scanned for hardcoded secrets using **TruffleHog**. "Verified findings were routed in real time to a Telegram group organized into over 100 source types," **Anthropic** detailed in its report.
'frkoo' also employed a separate automated process to collect **GitHub** organization email addresses, subsequently using them to obtain **GitHub Personal Access Tokens (PATs)**. These two pipelines provided critical initial-access credentials, which 'frkoo' then leveraged for the majority of confirmed breaches attributed to the actor. Further exacerbating their activities, 'frkoo' established a carding shop at policenationale[.]cc, impersonating the French national police to sell stolen payment card records and full cardholder information.
**ShinyHunters** affiliates were also observed stealing AI API keys, using them for breaching other organizations or for reconnaissance. In one notable instance, they breached a software-as-a-service provider, compromising data belonging to approximately 200 downstream customers.
### Accelerated Attacks with AI
**Anthropic**'s findings highlight the alarming speed at which AI can accelerate cyberattacks. A suspected **ShinyHunters** actor, utilizing **Claude AI**, managed to extract authentication data and acquire over 2,100 sets of **Azure AD** authentication tokens linked to more than 40 separate corporate **Microsoft** tenants in just 34 hours. **Anthropic** noted that "AI agents performed nearly all of the work."
Other harmful activities attributed to **ShinyHunters** affiliates, with **Claude**'s assistance, include breaching a technology provider to steal 1TB of data, compromising an airline, and accessing the systems of an energy company. The speed of these operations is striking; in one case involving an enterprise software firm, hackers progressed to bulk data theft within mere hours. Another instance saw an attacker move from a single stolen developer token to full administrative control in under three hours.
### State-Sponsored Espionage Leveraging AI
**Anthropic**'s report also sheds light on the involvement of state-sponsored groups. The Russian espionage group **Midnight Blizzard** utilized **Claude** to automate various stages of their operations, including malware development, research, infrastructure acquisition, phishing, persistence, command-and-control (**C2**) operations, and data exfiltration. The group even established a feedback loop to automatically rebuild malware upon detection by security products.
**Midnight Blizzard** targeted over 20 government, defense, diplomatic, intelligence, and foreign-policy entities. Their campaigns encompassed device-code phishing, **ClickFix** attacks, **DNS** hijacking via compromised hotel Wi-Fi, **WhatsApp** account takeovers, cloud-email theft, and deployment of Windows, Android, and iOS malware. **Claude** was integral to all attack stages, with **Midnight Blizzard** automating operations through AI-driven workflows and human operators primarily refining these skills.
Similarly, a Chinese-speaking espionage group, tracked as **GTG-10007**, employed **Claude** as the "engineering and orchestration layer of a coordinated offensive program." This involved:
* Intrusion attempts against production systems
* Reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia
* A standing vulnerability-research and exploit development effort against major endpoint-security products
* Malware development
* Building an intelligence-collection platform
**GTG-10007** developed autonomous vulnerability-research workflows, uncovering multiple previously unknown vulnerabilities in a major security product and delivering working exploits for several network and security appliances. These exploits were then leveraged against various government organizations globally. The group's operations targeted approximately 50 organizations across diverse sectors, with confirmed compromises in education-technology, retail, and a Southeast Asian government agency.
**Anthropic** has confirmed that it has disrupted these malicious uses of **Claude**, banned the associated threat actors' accounts, adjusted its guardrails based on observed misuse, and implemented measures for faster detection of future abuse. The company has also contacted authorities, industry partners, and victims.