Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-13 ยท updated: 2026-09-13 ยท tags: [incident, financial-services, android] ยท confidence: high ยท severity: low ยท affected_sectors: [financial-services] ยท au_impact: true

Anthropic's September threat-intelligence report also details financially motivated activity it attributed to actors linked to ShinyHunters, including an alleged French-speaking member using the handle "frkoo" who ran a credential-harvesting pipeline across ten AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs from multiple store sources, decompiled them and scanned for hardcoded secrets with TruffleHog, routing verified findings in real time to a Telegram group organised into more than 100 source types. A second automated pipeline collected GitHub organisation email addresses and used them to obtain personal access tokens, and Anthropic says the two pipelines supplied the initial-access credentials behind most of the actor's confirmed intrusions. In one case it says an affiliate extracted authentication data and more than 2,100 sets of Azure AD authentication tokens across more than 40 corporate Microsoft tenants in roughly 34 hours, with AI agents performing nearly all of the work, and describes movement from a single stolen developer token to full administrative control in under three hours elsewhere.

Attribute Detail
Sector Financial Services
Date 2026-09-13
Source Anthropic
Reliability Tier 1