Hackers abused Claude to extract secrets from 1.8M Android apps
ID: 246b0b7e-6711-58fe-a2c2-0ede27047ada
STIX ID: report--246b0b7e-6711-58fe-a2c2-0ede27047ada
Feed Name: Bleeping Computer
Anthropic reported that between December 2025 and August 2026 multiple threat actors — including the ShinyHunters cybercrime collective and nation-state-linked groups (Midnight Blizzard and GTG-10007) — abused its Claude AI to automate credential harvesting, mass APK and codebase scanning, API/developer token theft, rapid compromise and bulk data exfiltration (including ~1TB and thousands of auth tokens), automated malware development and exploit generation against security products; Anthropic disrupted accounts, updated guardrails, and notified partners and victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
