AI-speed attacks just stopped being a theoretical talking point. Anthropic, the company behind the Claude AI models, published a threat intelligence report this month detailing how multiple hacking groups — from financially motivated data thieves to state-sponsored espionage units tied to Russia and China — spent the better part of a year trying to turn Claude into part of their attack infrastructure.
The report covers activity Anthropic tracked between December 2025 and August 2026, and the details are a useful gut-check for any business leader who’s been treating “AI risk” as something that only shows up when employees misuse a chatbot. This report is about the other side of that coin: what happens when attackers use the same tools to launch AI-speed attacks.
A Credential-Harvesting Pipeline Aimed at 1.8 Million Apps
The most eye-catching case involves a suspected member of the ShinyHunters group, a collective already known for large-scale data theft tied to social engineering and account compromise. According to Anthropic, this actor built an automated pipeline across ten cloud servers that downloaded 1.8 million Android app files from multiple app stores, decompiled them, and scanned each one for hardcoded secrets — API keys, credentials, tokens — buried in the code. Verified finds were reportedly routed straight into a Telegram channel organized by more than 100 categories of secret.
A second, related pipeline harvested developer email addresses from GitHub and used them to obtain access tokens, feeding many of the same actor’s confirmed breaches. Anthropic says the group also used stolen AI API keys to breach other organizations and ran a criminal storefront that sold stolen payment card data, complete with an interactive map of victim addresses. These operations show how AI-speed attacks can scale credential harvesting far beyond traditional methods.
AI-Speed Attacks Unfold in Hours, Not Weeks
What stands out isn’t just the scale — it’s the speed. In one case tied to the same ShinyHunters-linked activity, it reportedly took roughly 34 hours to extract more than 2,100 sets of authentication tokens spanning over 40 separate corporate Microsoft tenants, with AI agents doing nearly all of the work. In another, an attacker went from a single stolen developer credential to full administrative control of a target environment in under three hours.
That’s the part worth sitting with. Traditional incident response timelines were built around attacks that unfold over days or weeks, giving defenders time to notice, investigate, and contain. When reconnaissance, credential harvesting, and privilege escalation collapse into a single afternoon, “we’ll review the alerts in the morning” stops being an adequate security posture against AI-speed attacks.
State-Sponsored Actors Are All in, Too
The report also details how a Russian espionage group Anthropic calls Midnight Blizzard used Claude to automate malware development, phishing infrastructure, and command-and-control operations against more than 20 government, defense, and diplomatic targets — even building a feedback loop that automatically rebuilt malware whenever it got flagged by security tools.
Separately, a Chinese-speaking group Anthropic tracks as GTG-10007 reportedly used Claude as an orchestration layer across an entire offensive program: reconnaissance, vulnerability research, exploit development, and building intelligence-collection tooling — with some of that vulnerability research running autonomously while human operators were away. The group’s targeting reportedly spanned roughly 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing.
Anthropic says it has since banned the accounts involved, tightened its guardrails, and notified affected organizations and law enforcement. That’s the right response from the vendor side — but it doesn’t undo the underlying shift the report documents regarding AI-speed attacks.
What This Means If You’re Not a Government Target
It’s tempting to read a report full of nation-state actors and multinational breaches and assume it’s someone else’s problem. It isn’t. The pipelines described above weren’t built to hit specific high-value targets — they were built to sweep broadly across app stores, code repositories, and cloud environments, and then hand attackers a ranked list of whatever they found. A small or mid-sized business with an exposed API key or an over-permissioned service account is just as visible to an automated scanner as a Fortune 500 company.
The same is true of the speed problem. AI-driven tooling doesn’t just help attackers targeting nation-states — it lowers the skill and time investment required for any attacker to move from initial access to full compromise. If a threat actor can go from one leaked token to admin control in under three hours, the gap between “we have a monitoring tool” and “we have 24/7 eyes on our environment” isn’t a nice-to-have anymore when facing AI-speed attacks.
How Black Belt Secure Helps You Keep Pace
This is exactly the scenario our MSSP and Jutsu vCISO clients are built to handle. Continuous monitoring catches the kind of rapid lateral movement described in this report while it’s happening, not after the fact. Regular credential and secrets audits close off the low-hanging fruit — exposed keys, stale tokens, forgotten service accounts — that automated harvesting pipelines are specifically designed to find. And a vCISO-led security program means someone is accountable for making sure your defenses evolve at the same pace the threat landscape does, instead of playing catch-up every time a new report like this one comes out.
Attackers have already figured out how to put AI to work at scale and deliver AI-speed attacks. The businesses that keep up will be the ones who do the same on defense.
Schedule a free consultation with Black Belt Secure and find out where your environment is exposed before an automated pipeline finds it for you.
Source: BleepingComputer, “Hackers abused Claude to extract secrets from 1.8M Android apps”, based on Anthropic’s September 2026 threat intelligence report.
