Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Anthropic threat report says hackers used Claude in a scan of 1.8 million Android apps

The AI company's September report details criminal and espionage groups using its models to automate secret harvesting, token theft and vulnerability research.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Anthropic says a ShinyHunters-linked actor used Claude to scan 1.8 million Android apps for hardcoded secrets.
  • 2The same cluster collected more than 2,100 sets of Azure AD tokens from over 40 corporate tenants in about 34 hours.
  • 3Anthropic says it banned the accounts and urges firms to treat AI API keys like production credentials.

The news

An Anthropic threat report covered by BleepingComputer on September 11 says a financially motivated actor linked to the ShinyHunters extortion crew used the company's Claude models in an operation that scanned 1.8 million Android apps for hardcoded passwords, keys and tokens.

The report covers misuse the company detected and disrupted between December 2025 and August 2026. It tracks the actor as GTG-50014. According to the report, the operation pulled 1.8 million unique Android app packages from several app stores, reverse-engineered their code and searched it for embedded credentials using TruffleHog, an open-source secret-scanning tool. BleepingComputer reported that the pipeline ran across ten Amazon Web Services cloud servers and pushed confirmed finds to a Telegram group as they came in, sorted into more than 100 source types.

Anthropic attributes other activity to the same cluster: more than 2,100 sets of Azure Active Directory authentication tokens tied to over 40 corporate Microsoft tenants gathered in about 34 hours, a breach of a technology provider that yielded more than a terabyte of data, and the compromise of roughly 200 downstream customer organizations through a software-as-a-service (SaaS) provider. The report says "AI agents performed nearly all of the work" in the token operation.

The report also describes espionage activity. Chinese-speaking operators Anthropic tracks as GTG-10007, likely based in China's Hunan province, used Claude to run and coordinate an offensive program, including vulnerability research, that targeted about 50 organizations; one of their automated workflows, aimed at network appliances, surfaced over a dozen potential zero-day flaws within a month. GTG-20006, which Anthropic describes as Russian state-linked espionage consistent with public reporting on Midnight Blizzard, used AI to modify and rebuild malware automatically when security tools detected it, targeting more than 20 organizations. A separate criminal actor compromised an AI vendor's evaluation sandbox to steal production API keys and hit roughly 30 AI companies in four days.

Anthropic said it banned the associated accounts, strengthened safeguards and shared intelligence with authorities and industry partners where appropriate. In the ShinyHunters case, the report and BleepingComputer both say the company also reached out to victims. The company said none of the cases involved its Fable or Mythos-class models, apart from one illicit distillation case. The findings are Anthropic's own account and have not been independently verified.

The numbers

Android apps scanned for secrets
1.8 million
Azure AD token sets collected
2,100+ from 40+ tenants in ~34 hours
Downstream organizations hit via one SaaS breach
~200
Organizations targeted by GTG-10007
~50

Why CEOs should care

For CISOs and mobile product owners, the lesson is that anything embedded in a shipped app should be treated as public. Scanning 1.8 million apps means attackers no longer need to pick targets; they collect every exposed cloud key and API token and sort the useful ones later. Ask your teams to scan current and past app builds for embedded secrets, rotate anything found, move credentials behind a server that issues short-lived tokens, and set alerts on unusual use of keys that ship in client code.

For CFOs and procurement leaders, the 200 downstream organizations tied to one SaaS provider breach is the number to remember. Vendor risk reviews should ask how suppliers store and scope the tokens that connect to your systems, how fast they can revoke them, and whether they would tell you within hours, not weeks. Contracts should give you the right to force rotation of any credential a supplier holds after a breach.

For boards, Anthropic's advice to treat AI API keys with the same rigor as production credentials points to a new asset class. Ask management who owns the inventory of AI service keys, what they can access and what they cost if stolen.

The bigger picture

The report describes attackers using models mainly to compress time and scale. It says campaigns that would have needed many skilled operators a year ago were run by individuals, citing breaches finished in two to three hours and single operators working against dozens of victims at once. Defenders' response windows shrink accordingly, which puts a premium on automated key rotation, anomaly detection and fast revocation. It also means the value of a leaked secret is realized quickly: once a key is public, companies should assume it has already been collected.

What’s next

Watch for app store operators and cloud providers to expand automated scanning for leaked secrets, and for victim companies tied to the SaaS breach to surface in notifications. Future reports from Anthropic and other AI providers will show whether account bans and new safeguards changed how these groups operate.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

AnthropicShinyHuntersAI securityApplication security

Earlier coverage of Anthropic

All Anthropic coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.