anthropic
A discount Claude reseller was neither cheap nor Claude
Claude News
anthropicCustomers of one discount Claude reseller were buying neither a discount nor Claude. In its September 2026 threat report, Anthropic says the group it tracks as GTG-50021 silently proxied their traffic to a different model while its tooling installed a credential harvester that took their Anthropic credentials and sold them on to other proxy resellers.
At a glance
- Anthropic's Threat Intelligence team says it disrupted operations between December 2025 and August 2026 across seven harm areas, on Claude Haiku, Sonnet and Opus; Fable and Mythos appear in one distillation case only.
- Stolen API keys pay three ways at once, the report says: resale value, attack compute billed to someone else, and cover, because the traffic is attributed to the key's legitimate owner.
- Anthropic says the keys involved came from customers' environments and that its own systems were not compromised; it also notes these are the most notable and novel cases, not typical misuse.
If you have not followed the series, Anthropic has been publishing case studies of Claude misuse since March 2025, with further reports in August and November. The November report described what the company called the first reported AI-orchestrated cyber espionage campaign, and in a February 2026 write-up Anthropic said it had identified industrial-scale distillation campaigns by DeepSeek, Moonshot and MiniMax.
GTG-50020 chased a pre-release Claude model across about thirty AI companies
GTG-50020 is a Russian-speaking, financially motivated actor with a history of intrusions into hotel booking and financial technology platforms. In one of those, the report says, the actor exfiltrated roughly 26 gigabytes from a single victim and sought between 1.5 and 2.5 million dollars, either through extortion or by selling the data on dark web forums.
The same tradecraft then turned on the AI industry. The actor injected malicious instructions into an AI vendor's automated evaluation sandbox and made it hand over the credentials it held, including production API keys from several providers, then ran further intrusion attempts on the victim's own keys.
A follow-on campaign from the same infrastructure hit roughly thirty AI companies in about four days, repeating one working path with small adaptations. The stated goal, pursued down more than a dozen avenues, was access to a pre-release Claude model. Every attempted path failed.
A French-speaking actor reached 14 of 42 tracked European targets
Operators who get AI credentials get loot, compute and cover in one move, the report argues, and one case shows what that buys. In spring 2026 a single French-speaking actor targeted European political parties, media, think tanks and their SaaS providers, using a custom Rust scanner to find and validate keys exposed in public containers, then rotating usage through a local proxy so the traffic blended with the legitimate owner's.
Across 42 tracked targets the actor gained internal access to at least 14 and took an estimated 12 to 26 gigabytes of database dumps, including party donor and member records. From one political campaign platform came about 140,000 records with users' political opinions. The actor also built fafsearch, a doxxing search engine loaded with tens of millions of rows and published on Tor, and Anthropic notes the whole platform was the work of one person.
Why does rotating a stolen key not stop the theft?
Because the harvester stays on the machine. The report describes sites posing as intermediaries that offer cheap access to frontier models, then push client applications that spoof popular AI harnesses, Claude Code among them. The installer collects every credential and session token on the device and keeps watching: when the compromised key is reset and a new session appears, that one goes out too. Think of a locksmith who keeps a copy of every new key you cut.
Keys leak by duller routes as well. Anthropic says multiple actors used prompt injection against wrapper services running LiteLLM to pull the production API keys held in their cloud-hosted containers, and that fraudulent resellers are mostly supplied by keys customers themselves exposed in apps, repositories, containers and websites.
GTG-50014 mined 1.8 million Android apps for hardcoded secrets
One operator among the suspected ShinyHunters affiliates ran a credential pipeline across ten AWS EC2 workers that downloaded 1.8 million distinct Android APKs, decompiled them and scanned for secrets with TruffleHog, routing verified hits into a Telegram group sorted by over 100 source types.
Speed is the theme. One breach of an enterprise software company took hours from first access to bulk data theft; another went from a single stolen developer token to full administrative control of a victim's cloud environment in roughly three hours.
After breaching a SaaS provider, operators dumped session stores holding over 2,100 Azure AD token sets across more than 40 corporate tenants in about 34 hours, with AI agents doing nearly all the work. When a victim's AI keys turned up mid-intrusion, the attackers switched their own workloads onto them.
Anthropic frames the selection itself: these are the most notable and novel cases it has found, not typical misuse, and it admits that for influence operations its visibility ends once content leaves Claude. In our view the disclosure is oddly asymmetric: the report names ShinyHunters affiliates and their aliases down to Telegram bot IDs, yet the AI vendor whose evaluation sandbox handed over production keys stays unnamed, as do the victim companies.
The keys still in your APKs
The report's instruction to customers is blunt: treat AI keys and agent integrations with the same seriousness as production credentials, and buy access only through authorized channels, since a discount that routes your traffic and credentials through an unknown intermediary is the pattern described here. Anthropic says it will keep evolving its safeguards and sharing intelligence with partners, and no date has been given for the next report in the series.
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
We only use your name and avatar from Google. We never store your email address.
