Security

Anthropic stops hackers after credential scan of 1.8 million apps

2 min read

TL;DR Too Long; Didn’t read

A threat report from Anthropic reveals: The hacker group ShinyHunters filtered out credentials from 1.8 million Android apps on a large scale using the AI model Claude. A single operator distributed the attack across ten cloud servers and funneled stolen passwords in real-time into sorted Telegram channels. Anthropic blocked the involved accounts and enhanced its detection against similar abuse.

An Anthropic logo sticker is affixed to a briefcase, spilling digital keys and open padlocks into a net of small app icons, while a masked figure types at a keyboard in the background. Image generated with GPT Image 2

Key takeaways

  • A single operator ran the scan pipeline in parallel on ten Amazon servers.
  • Stolen passwords and keys were funneled in real-time into more than a hundred sorted Telegram channels.
  • In addition to ShinyHunters, the report also names the Russian group Midnight Blizzard as a Claude user.
  • A Chinese-speaking group (GTG-10007) specifically searched for vulnerabilities in security products using Claude.
  • Anthropic's current report covers the period from December 2025 to August 2026.
  • The company blocked affected accounts and informed authorities as well as security partners.

The hacker group ShinyHunters used the AI model Claude from Anthropic to automatically search 1.8 million Android apps for hard-coded credentials. This is revealed in the current threat report published by Anthropic on September 10, 2026. A single operator distributed the attack pipeline across ten cloud servers and forwarded captured passwords in real-time to Telegram channels.

Automated pipeline searches millions of app packages

The attack began with the mass downloading of APK files from several app stores. A person operating under the aliases frkoo, MeowSHA, and blazespider, attributed to the ShinyHunters group, subsequently unpacked the programs and used the open-source tool TruffleHog to search for hard-coded credentials in the code. According to the threat report from Anthropic, Claude took on various tasks in automating and evaluating the data stream. The entire pipeline ran in parallel across ten working servers at Amazon Web Services. The apps came from both official stores and alternative marketplaces, indicating a broad-based search not limited to individual platforms.

According to the company, found passwords, API keys, and authentication tokens were forwarded in real-time to Telegram groups sorted by more than a hundred different types of secrets – from cloud accesses to payment service keys. The report does not publicly disclose how many of the 1.8 million app packages actually contained usable credentials; it is also independently unverified how many of the found credentials were still valid at the time of disclosure.

Report also documents state-sponsored attackers

The app scan is just one of several cases in the current Anthropic report, which covers the period from December 2025 to August 2026. The Russian group known as Midnight Blizzard, also referred to as APT29, reportedly used Claude to automate parts of classic espionage attack chains. A Chinese-speaking group, internally referred to by Anthropic as GTG-10007, utilized the model for independent vulnerability analyses and the development of exploits against security products.

Anthropic states that it has suspended the affected accounts in all three cases and introduced additional detection mechanisms against similar abuse. The company has also informed authorities, affected companies, and partners from the security industry. As Anthropic already admitted in the summer, these are not the first security incidents surrounding its models this year – at that time, test environments had unintentionally gained access to foreign systems. The current report, however, concerns the targeted, intentional use by criminals and allegedly state-sponsored groups.

It will be crucial whether account suspensions can effectively combat such distributed and anonymous abuse as long as AI accesses remain available through open APIs and resellers. Anthropic announces stricter automated abuse detection; whether it will stop similar campaigns before a million-fold scan will be shown at the earliest in the next threat report.

Frequently asked questions

Who is behind the app scan?

Anthropic attributes the campaign to an operator who appears under the aliases frkoo, MeowSHA, and blazespider and is part of the financially motivated group ShinyHunters.

Are my own credentials at risk due to the incident?

Developers who had hard-coded passwords or API keys in the app code are primarily affected. Anyone using an app with such a vulnerability should proactively change affected accesses, even though Anthropic has not published a public list of the apps.

What has Anthropic done to combat the abuse?

The company blocked the associated accounts, tightened automated detection of similar patterns, and informed authorities as well as affected companies.

Does the report only concern Claude or other AI models as well?

The report documents exclusively abuse cases related to Claude. Other security incidents involving AI at Anthropic, such as unintended accesses during security tests in July 2026, had different causes.

Where can the full report be read?

Anthropic publishes the threat report as a website and PDF at anthropic.com; it contains more detailed technical information on all cases mentioned in the article.

Sources (2)
  1. Anthropic: Threat Intelligence Report, September 2026
  2. Bleeping Computer: Hackers abused Claude to extract secrets from 1.8M Android apps

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog