{ "actor": "Suspected ShinyHunters affiliates (tracked by Anthropic as GTG-50014)", "actor_type": "cybercriminal", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "load-bearing", "autonomy_level": "supervised-autonomous", "autonomy_pct": null, "category": "ai-orchestrated-campaign", "confidence": "primary", "date_disclosed": "2026-09-10", "guardrail_bypass": [ "unknown" ], "id": "gtg-50014-agentic-mass-exfiltration", "impact": "Per Anthropic: more than a terabyte of data exfiltrated from a technology provider, including hundreds of thousands of national identifiers and millions of payment card records; tens of millions of passenger records from an airline; over 2,100 Azure AD token sets across more than 40 corporate tenants; a SaaS provider compromise exposing roughly 200 downstream customer organizations; a ~400,000-record telecom/ISP dataset aggregated into a searchable service. Pay-or-leak extortion is the stated business model.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "credential-access", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Anthropic detected and banned accounts associated with the ShinyHunters associates, implemented measures to detect and disrupt future misuse from the actors, and engaged government authorities, industry partners and victims to remediate." ], "model_families": [ "claude" ], "models": [], "name": "GTG-50014 ShinyHunters-linked agentic mass data theft and extortion", "related": [ "gtg-2002-vibe-hacking-extortion", "gtg-20006-agentic-espionage", "gtg-10007-agent-swarm-intrusions", "gtg-50029-hacktivist-agentic-recon", "gtg-50020-ai-vendor-api-key-theft" ], "severity": "critical", "sources": [ { "archive_url": "https://web.archive.org/web/20261009173227/https://www.anthropic.com/threat-intelligence-report-september-2026", "date": "2026-09-10", "publisher": "Anthropic", "title": "Countering misuse of AI: September 2026", "type": "first-party-disclosure", "url": "https://www.anthropic.com/threat-intelligence-report-september-2026" } ], "status": "confirmed", "summary": "In its September 2026 report \"Countering misuse of AI\", Anthropic disclosed a financially motivated cluster it tracks as GTG-50014, whose operators it describes as \"suspected to be affiliates of the ShinyHunters collective\". Between December 2025 and August 2026 the affiliates used Claude across multiple intrusions: a technology provider lost more than a terabyte of data including hundreds of thousands of national identifiers and millions of payment card records; an airline lost tens of millions of passenger records; an energy company, a French retail chain, a Web3 identity platform, a nonprofit and an enterprise software company were also hit; and a SaaS provider compromise reached roughly 200 downstream customer organizations. Over 2,100 Azure AD token sets spanning more than 40 corporate tenants were harvested in about 34 hours. Anthropic states that for the SaaS session-store dump \"AI agents performed nearly all of the work\", with humans setting targets and reviewing exfiltration. Anthropic detected and banned the associated accounts and engaged authorities, industry partners and victims.", "targets": { "countries": [ "FR" ], "orgs_affected": null, "records_exfiltrated": null, "sectors": [ "technology", "energy", "retail", "telecommunications", "aviation", "nonprofit" ] } }