Threat groups abused Claude AI to steal Android app secrets

Anthropic disclosed on September 12, 2026, that multiple threat groups, including financially motivated actors and state-sponsored espionage teams linked to Russia and China, abused Claude between December 2025 and August 2026 to extract secrets from 1.8 million Android apps. Stolen credentials included API keys and tokens.

5 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. h

mastodon:infosec-exchangeother18d ago kagi ↗

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. https://www. bleepingcomputer.com/news/secu rity/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/

🤖 Threat actors abused Anthropic's Claude to extract secrets (API keys, tokens) from 1.8M Android apps. Financially motivated and state-sponsored espionage groups linked to Russia and China misused t

mastodon:infosec-exchangeother18d ago kagi ↗

🤖 Threat actors abused Anthropic's Claude to extract secrets (API keys, tokens) from 1.8M Android apps. Financially motivated and state-sponsored espionage groups linked to Russia and China misused the model for data theft. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/ # AI # CyberSec # InfoSec

🤖 Anthropic: threat groups — incl. state-sponsored actors linked to Russia and China — abused Claude to automate exploitation and extract secrets from 1.8M Android apps (Dec 2025–Aug 2026). Credentia

mastodon:infosec-exchangeother17d ago kagi ↗

🤖 Anthropic: threat groups — incl. state-sponsored actors linked to Russia and China — abused Claude to automate exploitation and extract secrets from 1.8M Android apps (Dec 2025–Aug 2026). Credential harvesting, espionage tooling. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/ # CyberSec # AI # InfoSec # Malware