securityaffairs.com 12 Sept 2026, 16:46 UTC

Anthropic Finds AI Scaling Credential Theft and Global Operations

Anthropic Finds AI Scaling Credential Theft and Global Operations

ANTHROPIC’S Threat Intelligence report for December 2025 to August 2026 portrays AI not merely as a tool but as a functioning operational layer for diverse actors. A standout case involved a financially motivated operation that harvested credentials from software and online services by mass-downloading 1.8 million Android APKs, decompiling them and scanning for hardcoded secrets with a pipeline that fed real-time findings to a Telegram group and a parallel stream of GitHub Personal Access Tokens.

The attackers used Claude to design and test tooling, assemble malware and phishing resources, and exfiltrate data, with tokens replayed against Microsoft services to access mailbox contents. This demonstrates how AI can automate multiple stages of an intrusion, allowing a smaller team to mount attacks at scale.

Beyond cybercrime, Anthropic documents surveillance, propaganda, fraud and weapons development using Claude. Nation-state and commercial surveillance actors recruited Claude to monitor populations, profile individuals and analyse social-media content, including crafting messages in dialects and automating intelligence workflows.

In influence operations, AI-enabled networks of hundreds of inauthentic accounts produced propaganda and dossiers on public figures; in consumer fraud, AI personas interacted with users across dozens of dating apps. The report also notes six cases of weapons development or intelligence gathering—ranging from guided rockets and autonomous drone swarms to anti-torpedo systems—where AI accelerated research, documentation and testing, often alongside existing expertise.

It also highlights AI supply-chain risks where firms siphoned workloads through fraudulent accounts to extract model capabilities. The practical response urged is ongoing Safeguards evolution, robust detection, and disruption of misuse as AI becomes a multiplier across attacker playbooks.

View full article

Article by CyberSIXT