-
The research of Anthropic reveals that ShinyHunters members have employed artificial intelligence devices to acquire secrets from 1.8 million Android packages, and they have created an automated pipeline for breaching corporate networks.
-
Attackers used automated AI workflows to achieve full cloud administrative takeover from a single stolen token in just three hours, exfiltrating terabytes of airline, payment card, and SaaS data.
-
AI-driven intrusions targeting cloud and SaaS providers resulted in the compromise of over 2,100 Azure AD token sets and exposed data from thousands of downstream customer organizations.

The AI developer Anthropic recently released a report to detail how modern criminal groups utilize AI technology for massive data theft operations. Discoveries show that criminal organizations connected with ShinyHunters affiliates are using AI agents to make targeting easier. Also, such criminal groups collect secrets and compromise the cloud systems of many enterprises with these tools.
Instead of using AI merely as a writing aid, attackers now assign complete operational tasks directly to autonomous systems. Consequently, criminals can easily carry out sophisticated multi-stage attacks on big technology companies, international airlines, and software applications with very little human intervention.
AI-Driven Secret Harvesting Scans Millions of Mobile Applications
The threat report highlights an extraordinary initial access pipeline created by a malicious operator using autonomous AI tools. The assailant utilized automated processes to obtain and reverse-engineer 1.8 million Android APK files to find hidden passwords. AI software took control of the code for these applications and, in real-time, and identified exposed API keys and private tokens, and admin passwords.
Next, the automated pipeline forwarded these verified credentials directly into active initial-access systems to launch secondary network attacks. The attacker then used these stolen GitHub keys to breach connected corporate repositories and access internal cloud environments. This automated scanning framework turned mobile application code into a high-speed launchpad for massive enterprise intrusions.
Furthermore, delegating code analysis to AI agents removes traditional technical barriers for low-skilled threat actors. The perpetrators no longer have to rely on sophisticated reverse engineering capacities to seek zero-day vulnerabilities or uncovered program keys. Thus, the effectiveness of automated algorithms based on AI helps save multiple hassles and minimize the costs involved in cyberattacks.
Rapid Escalation to Cloud Administrative Takeovers and Mass Data Theft
The intelligence report describes several significant company intrusions that have led to serious data leakage in different industry sectors. For example, in one of the attacks, the hackers managed to gain administrative access to the cloud system, using only one stolen token. The threat actor completed this total administrative takeover in roughly three hours through automated privilege expansion scripts.
In addition, another incident at one of the largest IT companies saw the criminals stealing more than 1 terabyte of sensitive data. This single breach exposed millions of active customer payment card records alongside internal infrastructure details. In another incident, the airline sector suffered from serious data leakage that exposed records of tens of millions of passengers.
In other cases, the attackers targeted cloud management systems and hacked several companies at a time. They stole over 2100 Azure AD tokens, spanning over 40 distinct corporate tenants within 34 hours. These rapid token extractions highlight how quickly automated workflows can compromise isolated cloud environments across complex global networks.
The speed of these attacks reflects a broader shift in AI-powered credential theft. Google has also warned that hackers are using AI agents to steal thousands of credentials in under six hours, showing how quickly automated systems can turn exposed accounts into an access point.
Software Supply Chain Vulnerabilities Amplify Downstream Customer Exposure
Software-as-a-Service platforms have become primary targets for AI-assisted supply chain attacks due to their central network access. By breaching only one upstream cloud service provider – attackers could compromise hundreds of customer databases at once.
Thus, they have no need to hack into individual systems separately. One of the incidents demonstrated how a single breach of the SaaS provider allowed thieves to obtain sensitive data from around 200 downstream companies.
In addition to this, one more breach of a different SaaS supply chain allowed attackers to steal proprietary information from thousands of downstream corporate clients. Anthropic noted that AI agents performed nearly all the technical labor during these complex multi-stage exfiltration tasks. The AI systems conducted environment analysis, generated custom extraction scripts, and organized stolen files without continuous human oversight.
In response to these findings, Anthropic terminated all malicious accounts associated with the identified threat clusters. The company also upgraded its internal models for detecting cases of abuse to prevent automatic authentication checks and scripting violations. Moreover, Anthropic shared information on threat intelligence with law enforcement authorities, security partners, and impacted businesses to aid remedial processes.
Essential Enterprise Security Defenses Against AI-Powered Intrusions
To combat AI-driven attacks, enterprise defense teams must modernize their internal credential management practices and secret monitoring workflows. Organizations must conduct regular audits of public source code repositories to prevent developers from hardcoding API keys inside production software. Implementing automated secret scanners helps security operations centers identify and revoke exposed tokens before attackers discover them.
In addition to secret scanning, cybersecurity teams should implement robust zero-trust access policies for all cloud identity providers. Using ephemeral session tokens and ultra-secure two-step authentication stops hackers from taking advantage of hacked Azure AD tokens to achieve permanent entry. Network managers must also restrict permission levels to minimize lateral movement in the event that one developer account is compromised.
Corporate security departments need to make sure to monitor their terminal activities. This helps them to find any unusual API call activity and excessive acquisition of permissions. This allows them to take timely measures to protect their network from intrusions. They can also stop breaches from happening before it is too late. As cybercriminals use AI technology, threat hunting strategies have become vital for enterprise software supply chain security.