Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [incident, campaign, ai-uplift, cybercrime-group, sector-technology] ยท confidence: medium ยท severity: high ยท affected_sectors: [technology, finance, government] ยท au_impact: true

GTG-50014 โ€” Suspected ShinyHunters Affiliates Run AI-Uplifted Credential Harvesting

Summary

Multiple clusters of financially motivated activity, assessed by Anthropic as affiliates of the ShinyHunters collective, used Claude to uplift an opportunistic smash-and-grab model: mass credential harvesting, exploitation of unpatched internet-facing systems, data theft and pay-or-leak extortion. The clusters used their own tooling and workflows but shared an attack lifecycle and objective, and the vendor disrupted the activity. The case is the report's headline example of uplift widening an existing criminal ecosystem rather than creating a new one.

Key Facts

  • Attack lifecycle: credential harvesting โ†’ target access โ†’ movement to databases and customer data โ†’ extortion, or for SaaS providers, use of the stolen data against the provider's own customers with a pay-or-leak threat.
  • Harvesting pipeline: one French-speaking operator (aliases MeowSHA / frkoo / blazespider) ran a distributed pipeline across a fleet of 10 AWS EC2 workers. It mass-downloaded 1.8 million distinct Android APKs, decompiled them and scanned for hardcoded secrets with TruffleHog; verified findings were routed in real time to a Telegram group organised into more than 100 source types. A parallel GitHub organisation email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two streams supplied initial access for the bulk of the confirmed breaches attributed to the operator.
  • Operational security was mixed: the same operator exposed their own EC2 staging IP, multiple Telegram bot tokens, a Squid proxy with hardcoded credentials and at least one public paste-site upload inside a victim environment.
  • Criminal storefront: the actor registered policenationale[.]cc, impersonating the French national police, as branding for a carding shop ("fiches" enriched with BIN lookups, full cardholder PII and an interactive geolocation map of victim addresses), distributed through a Telegram Mini App backed by a PostgreSQL/GraphQL platform that also aggregated multiple French breach datasets, including a ~400,000-record telecom/ISP dataset with IBANs and BICs.
  • Victim impact: one technology provider lost more than a terabyte of data including hundreds of thousands of national identifiers. A retail chain was compromised and a Web3 identity platform probed in secondary attacks run off a stolen key.
  • Stolen AI keys as a pivot: during multiple intrusions, the operators stole a target's AI API keys from the target's enterprise software vendors, then used one stolen key for roughly three weeks of secondary attacks against other organisations. This is the report's clearest illustration that third-party AI integration is now part of an enterprise's attack surface.

Significance

The extortion model described โ€” enter a SaaS or enterprise vendor, steal customer data, then leverage it against the vendor's customers under a leak threat โ€” matches the ShinyHunters-branded incidents in this vault (for example Carhartt Breach Shinyhunters Releases Data Of 12 9 Million Accounts and the healthcare theft campaign flagged by Health-ISAC). What is new here is the industrialisation of the harvesting stage: 1.8 million application packages scanned for secrets, with findings triaged in real time. Organisations cannot treat mobile application packages, public repositories and container images as non-production surfaces.

Sourcing caveat

Single-source vendor disclosure. The grouping of disparate operator clusters into "suspected affiliates of the ShinyHunters collective" is the vendor's assessment based on shared objectives and lifecycle, not a confirmed organisational structure.

Related: Ai Uplift, Generative Threat Groups, Mcp Tool Poisoning, Shinyhunters