NAIROBI, Kenya- Hackers linked to the ShinyHunters cybercrime collective accessed systems containing tens of millions of airline passenger records during a series of AI-assisted attacks, according to a new report by artificial intelligence company Anthropic.
The airline was not identified in Anthropic’s September 2026 Threat Intelligence Report, which documented malicious activities detected and disrupted between December 2025 and August 2026.
Anthropic said the airline intrusion was part of a wider campaign conducted by financially motivated operators suspected of being ShinyHunters affiliates.
The attackers used Claude to accelerate the discovery of stolen credentials, understand unfamiliar computer systems, gain greater access and extract large quantities of information.
Although the suspected affiliates appeared to use different tools and operational methods, Anthropic said their approaches and objectives indicated that they were participating in the same broader criminal operation.
Hackers scanned 1.8 million Android apps
One French-speaking operator, identified in the report by the aliases MeowSHA, frkoo and blazespider, operated a credential-harvesting system across 10 Amazon Web Services cloud servers.
The system downloaded approximately 1.8 million Android application packages from several app stores, decompiled them and searched their code for exposed credentials and other sensitive information.
Verified credentials were automatically forwarded to Telegram groups organised into more than 100 categories.
The operator also harvested email addresses connected to GitHub organisations and searched for stolen GitHub personal access tokens. According to Anthropic, these automated pipelines supplied credentials used to gain initial access during several confirmed breaches.
The operation searched application files, public code repositories, websites, container images, cloud storage and other internet-facing systems for passwords, tokens and application programming interface keys.
Stolen credentials were then tested to determine whether they were active and valuable before being used, stored or sold.
More than one terabyte stolen
In one of the most serious incidents, the attackers compromised a technology provider and extracted more than one terabyte of information.
The stolen material included hundreds of thousands of national identification records and millions of payment card records, according to the report.
The attackers allegedly placed the information on a publicly accessible website to pressure the company into paying a ransom.
At an unnamed airline, the operators accessed systems holding tens of millions of passenger records. Anthropic did not disclose whether all the records were extracted, what information they contained or whether the airline received an extortion demand.
Another attack targeted an energy company. The hackers said they could remotely control the charging current of electric-vehicle chargers installed in customers’ homes, although the report did not independently establish whether they exercised that capability.
Companies used to reach their customers
The attackers also targeted software providers as a route into other organisations.
After compromising one software-as-a-service company, an operator extracted information belonging to approximately 200 of its customers.
The attacker subsequently dumped more than 2,100 Microsoft Azure Active Directory token sets covering more than 40 corporate tenants in about 34 hours.
In a separate supply-chain intrusion, the hackers exploited a cross-site scripting vulnerability at another software provider before escalating their privileges and extracting information from thousands of downstream customers.
Claude helped the operator understand developer and authentication interfaces, create privileged tokens and develop tools for bulk data exports across multiple customer accounts, Anthropic said.
The company described the technique as “vibe hacking,” in which an attacker gives an AI agent a broad objective and allows it to inspect the target environment, write and execute programs, retrieve information and repeat the process until the assignment is completed.
“AI agents performed nearly all of the work,” Anthropic said of one supply-chain operation.
Breaches completed within hours
Anthropic said AI significantly increased the speed of the attacks.
One enterprise software company was breached and subjected to bulk data theft within hours. In another case, a single stolen developer token was used to obtain full administrative control of a victim’s cloud environment in approximately three hours.
The attackers then searched internal databases and, where software suppliers were involved, accessed information belonging to their customers.
Anthropic also found that some operators stole AI application programming interface keys from compromised companies and used them to conduct further attacks. One stolen key was used for about three weeks in operations that included compromising a French retail chain and probing a Web3 identity platform.
The company stressed that the keys were stolen from customers’ environments and that Anthropic’s own systems were not breached.
Anthropic said it banned accounts associated with the suspected ShinyHunters affiliates, introduced additional safeguards and worked with government authorities, industry partners and affected organisations to address the threats.




