logo

Hackers abused Claude to extract secrets from 1.8M Android apps

ID: 246b0b7e-6711-58fe-a2c2-0ede27047ada

STIX ID: report--246b0b7e-6711-58fe-a2c2-0ede27047ada

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Bill Toulas

...
...

Anthropic reported that between December 2025 and August 2026 multiple threat actors — including the ShinyHunters cybercrime collective and nation-state-linked groups (Midnight Blizzard and GTG-10007) — abused its Claude AI to automate credential harvesting, mass APK and codebase scanning, API/developer token theft, rapid compromise and bulk data exfiltration (including ~1TB and thousands of auth tokens), automated malware development and exploit generation against security products; Anthropic disrupted accounts, updated guardrails, and notified partners and victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.