ShinyHunters at Scale: A Case Study in AI-Assisted Cybercrime

ShinyHunters has built its reputation by stealing data at scale, often without relying on sophisticated malware. Now it’s using AI to supercharge its playbook.

Assaf Morag
Sep 24, 2026

ShinyHunters has built its reputation by stealing data at scale, often without relying on sophisticated malware. The cybercriminal group has used a wide array of methods to gain access to systems, and now it’s using AI to supercharge its playbook. 

One intrusion Anthropic documented showed a suspected ShinyHunters affiliate moving from a single stolen developer token to full administrative control of a cloud environment in roughly three hours. In another, AI agents did nearly all the work to produce more than 2,100 Azure AD token sets in 34 hours. 

AI now shows up at every stage of that pipeline: discovering credentials and accelerating cloud compromise, analyzing terabytes of stolen data, and even creating new attack techniques through automation. The result is attacks run at a speed that gives you hours, not days, to respond.

‍

‍

Same Operation, New Tools

In a blog on ShinyHunters’ tactics from earlier this year, we described ShinyHunters as an example of a broader change in data breaches: “Access is the new exploit.” Instead of depending on custom malware, attackers frequently obtain legitimate credentials, tokens, SaaS sessions, or application permissions and use the same APIs and export functions available to real users. 

Once inside, the threat actors start hunting for data. Often the goal is to simply extract as much of it as possible before access disappears.

Anthropic's September 2026 threat intelligence report gives us a clearer view of what happens when AI is inserted into that equation. The AI lab identified multiple financially motivated projects operated by what it describes as suspected ShinyHunters affiliates and shows how AI repeatedly helped reduce the human labor involved in turning exposed access into compromised organizations.

From 1.8 Million APKs to Access

Anthropic reported a French-speaking individual affiliated with ShinyHunters who used the aliases MeowSHA, frkoo, and blazespider ran a credential-harvesting operation across 10 AWS EC2 workers. That pipeline downloaded 1.8 million distinct Android APKs, decompiled them, and scanned them for hardcoded secrets using TruffleHog. At the same time, another pipeline harvested GitHub information and Personal Access Tokens.

Anthropic says those credential pipelines supplied the initial-access credentials behind the bulk of the confirmed breaches associated with ShinyHunters.

Finding secrets inside artifacts like APK packages isn’t new. What is new and troubling is the scale — over 1.8 million distinct packages — and using AI to classify and prioritize the initial results from a credential scanner.

Lateral Movement: From Access to Impact in Several Hours

In another case Anthropic described, a suspected ShinyHunters affiliate compromised a SaaS provider and obtained data belonging to roughly 200 downstream customer organizations. Anthropic’s report noted that “AI agents performed nearly all of the work,” producing more than 2,100 Azure AD token sets across more than 40 corporate tenants in just 34 hours.

In a different compromise, Claude helped the attacker identify and work with developer and authentication APIs, create or convert privileged tokens, and build tooling for bulk exports and cross-tenant collection.

Still another intrusion progressed from a single stolen developer token to full administrative control of a cloud environment in roughly three hours.

Processing the Stolen Data

Threat actors are now dealing with the same problem legitimate businesses face: how to mine vast amounts of data for the most valuable pieces of information. After stealing a large filesystem, the attacker still needs to understand what it contains, because it can significantly change the potential profits from the attack and consequently the extortion strategy. And LLMs provide a powerful way to automate the harvesting, analysis, and classification of that data at scale.

Google Threat Intelligence Group recently observed ShinyHunters employing AI as part of its attack lifecycle. In its September AI Threat Tracker, Google documented ShinyHunters using Claude Code configured with custom MCP tools to parse and analyze exfiltrated directories for extortion.

In another ShinyHunters attack this year targeting the National Association of Insurance Commissioners, the group claimed to have stolen approximately 3.1 TB of data. It initially characterized portions of the dataset as significantly more sensitive than NAIC's subsequent investigation found. NAIC said much of the stolen information consisted of already-public statutory financial reporting information, credit-rating data, and routine technical material.

ShinyHunters later blamed the mistake on using AI to analyze the data. The NAIC case provides an interesting example of both the potential and the limitations of using AI to analyze stolen data. It also verifies that ShinyHunters uses AI to analyze stolen data at scale.

Using AI to Target the Human Attack Surface

ShinyHunters’ use of AI is not limited to the technical attack pipeline. It is also expanding another attack vector that has historically played a smaller role in its operations: social engineering.

Voice phishing, or vishing, has become an important initial-access technique in ShinyHunters-branded campaigns. Attackers call employees impersonating IT or help-desk personnel and try to convince them to provide credentials or MFA codes or to take other actions that ultimately give the attacker access to corporate identity and SaaS environments. Google has documented ShinyHunters-branded operations combining sophisticated vishing with victim-specific credential-harvesting sites to obtain SSO credentials and MFA codes before moving into cloud applications and stealing data.

EclecticIQ reported that ShinyHunters-linked actors took this model a step further by abusing legitimate commercial platforms including Vapi and Bland AI to automate social-engineering calls. This is much more advanced than traditional robocalling or playing a pre-recorded message. Bland AI's LLM-based conversational pathways can be configured around a scenario and dynamically adjust the conversation when a target responds unexpectedly. Attackers can also configure characteristics such as voice style, gender, regional accent, and tone, allowing the interaction to remain convincing without following a rigid script.

Traditional vishing is expensive for attackers and doesn’t scale because every simultaneous conversation generally requires another human operator who can interact with the victim, answer questions, maintain the pretext, and guide the victim toward the desired action. AI voice agents can automate much of that work and repeat it across far more targets — the attacker just designs the scenario.

For Defenders, the Clock Is Speeding Up

The lesson for defenders is that they should first and foremost know what type of data is in their environments and how sensitive it is. AI can help threat actors fully understand the victim’s environment, write the necessary tooling, evaluate results, and repeat the process across many targets. That means a control failure that once took significant human effort to exploit can become much easier to attack at scale. 

Authentication mechanisms, along with MFA and secrets management, remain critical. But a successful authentication (particularly when attackers possess legitimate sessions or tokens) is no longer the end of the security question. It is the beginning of the data question and that makes several defensive questions more urgent: 

  • Where are credentials and API keys exposed? 
  • Which OAuth applications and integrations have broad access? 
  • Which human and machine identities can reach sensitive data? 
  • What happens if one SaaS provider or developer token is compromised? 
  • Can the organization identify unusual bulk access or exfiltration quickly enough when the attack may progress in hours rather than days?
  • Most important of all, what sensitive data is reachable from a compromised identity?

AI is Boosting the Capabilities of ShinyHunters

Taken together, the research illustrates how ShinyHunters is inserting AI across almost its entire attack pipeline. It begins before the breach, helping sift through millions of applications, repositories, and exposed secrets to identify credentials worth exploiting. 

Once threat actors have access, AI agents can help navigate APIs, privileges, tokens, cloud environments, and downstream tenants, accelerating the path from a single credential to large-scale data collection. After exfiltration, LLMs and MCP-enabled tooling can analyze enormous stolen datasets, identify sensitive information, and determine which data provides the greatest leverage for extortion. At the same time, AI voice agents can scale the human side of initial access by automating parts of vishing that previously required humans. 

The underlying ShinyHunters model has not fundamentally changed: find access, exploit legitimate permissions, steal valuable data, understand its value, and monetize it through extortion. What AI changes is the speed and scale at which that pipeline operates.

‍

Compartir