The AI company detailed the abuses in a threat intelligence report, noting that over the eight-month period it recorded misuse spanning cyber operations, influence campaigns, surveillance, scams, and attempts to develop biological and conventional weapons. Anthropic said it disrupted several activities linked to the ShinyHunters hacking collective.
An alleged French-speaking member using the handle 'frkoo' distributed a credential-harvesting pipeline across ten AWS EC2 workers. The pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app stores, decompiled them, and scanned for hardcoded secrets using the open-source tool TruffleHog. Verified findings were routed in real time to a Telegram group organized into over 100 source types.
The same actor also ran a separate automated process to collect GitHub organization email addresses, which were used to obtain GitHub Personal Access Tokens. These two pipelines provided initial-access credentials that 'frkoo' used for the bulk of confirmed breaches associated with the hacker, according to Anthropic. 'frkoo' also set up a carding shop impersonating the French national police to sell stolen payment-card records.
In addition, suspected ShinyHunters members stole AI API keys and used them for reconnaissance or to breach other organizations. In one case, they compromised a software-as-a-service provider and stole data belonging to around 200 downstream customers.
Anthropic highlighted the speed enabled by AI agents. In one instance, a suspected ShinyHunters member used Claude to extract more than 2,100 Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants in approximately 34 hours. "AI agents performed nearly all of the work," the company stated.
Other harmful activity attributed to ShinyHunters affiliates includes breaching a technology provider and stealing 1 terabyte of data, compromising an airline, and accessing systems of an energy company. In the case of an enterprise software firm, the hackers moved from initial access to bulk data theft in just a few hours.