Hackers Used Claude AI To St£al Millions Of Records, Over 2,100 Authentication Tokens, Report Says

 

Hackers Used Claude AI To Steal Millions Of Records, Over 2,100 Authentication Tokens, Report Says

The AI firm said it found out that they had used Claude to dramatically accelerate large-scale data theft and extortion campaigns.

Anthropic, the American artificial intelligence research and safety company behind the Claude family of large language models, said it disrupted several clusters of financially motivated hackers believed to be affiliated with ShinyHunters, one of the most prolific data-extortion collectives currently operating.

The AI firm said it found out that they had used Claude to dramatically accelerate large-scale data theft and extortion campaigns.

According to the company’s newly released threat intelligence report, although the affiliated hackers appeared to operate independently with their own tools, an analysis of their methods and targets showed they were part of the same broader criminal operation, exploiting stolen data for pay-or-leak extortion schemes.

One French-speaking operator, using the aliases “MeowSHA,” “frkoo” and “blazespider,” ran a credential-harvesting pipeline across a fleet of ten cloud computing servers that mass-downloaded 1.8 million Android application files, decompiled them, and scanned them for hardcoded passwords and access keys.

The operator also registered a domain impersonating the French national police to serve as a storefront for a “carding” operation selling stolen payment card records enriched with personal information and interactive maps of victims’ addresses.

The report described several of the group’s most serious breaches. In one, operators exfiltrated more than a terabyte of data from a technology provider, including hundreds of thousands of national identity records and millions of payment card numbers, before publishing the stolen material online to pressure the company into paying a ransom.

In another, hackers accessed an airline’s systems containing tens of millions of passenger records, while at an energy company, the operators claimed they could remotely control the charging current of electric vehicle chargers installed in customers’ homes.

In a separate supply-chain attack, one affiliate breached a software provider and used the access to extract data belonging to roughly 200 of that company’s downstream business customers, later dumping more than 2,100 stolen authentication tokens spanning over 40 corporate accounts, a process the report said took only around 34 hours, with AI agents performing “nearly all of the work.”

Anthropic described the pattern as resembling what it called “vibe hacking,” where operators direct AI to achieve general goals and then let it independently evaluate the target environment, write and run code, and repeat the process until the task is complete, often without the operator fully understanding the systems being compromised.

Anthropic said it has banned the accounts associated with the ShinyHunters affiliates, deployed new measures to detect similar activity in future, and engaged law enforcement, industry partners and affected victims to help remediate the damage.

 

 

CATEGORIES
Share This

COMMENTS

Wordpress (0)
Disqus ( )