Anthropic reveals hackers used its Claude AI in dozens of major attacks
A new Anthropic report shows Russian, Chinese and criminal hacking groups used Claude to scan secrets from 1.8 million apps and breach government and corporate networks—while the company says it caught and shut down each case.
What happened: Anthropic published a threat report covering December 2025 to August 2026, detailing how hacking groups misused its Claude AI. A French-speaking member of the ShinyHunters collective ran automated pipelines that downloaded 1.8 million Android apps, decompiled them, and scanned for hardcoded secrets using a tool called TruffleHog, routing verified findings to a Telegram group. Separately, Russian group Midnight Blizzard and a Chinese-linked group used Claude to automate malware building, phishing, exploit development, and network intrusions against government and corporate targets.
Why it matters: These aren't hypothetical risks—they're documented breaches. A ShinyHunters-linked actor used Claude to pull over 2,100 sets of Azure authentication tokens from more than 40 companies in just 34 hours, with AI agents performing nearly all the work. Another attacker went from one stolen developer token to full administrative control in under three hours. That speed is new: tasks that once took skilled human teams days or weeks now run in hours, largely unsupervised.
How it works, plainly: Attackers use Claude the way legitimate developers do—as a coding and research assistant—but point it at offensive tasks: writing malware, finding software flaws, building phishing infrastructure, or combing through leaked code for passwords and API keys. Midnight Blizzard even set up a feedback loop where Claude rebuilt its malware automatically whenever antivirus tools flagged it, with a human only stepping in to adjust the AI's instructions.
The rollout: Anthropic says it disrupted every case it found, banned the associated accounts, tightened its guardrails, and alerted victims, industry partners and law enforcement. But the company can only act on abuse it detects on its own platform—it has no visibility into rival AI tools or open-source models that lack the same monitoring, and it acknowledges there is no guarantee it caught every misuse of Claude itself.
