Anthropic report details a failed Houthi rocket test and a ShinyHunters pipeline that scanned 1.8 million Android apps
Users in northern Yemen returned to Claude to ask why their guided rocket failed, while a French-speaking ShinyHunters member ran secret-scanning across ten AWS workers.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
New details are emerging from Anthropic's eight-month threat report covering December 2025 to August 2026. BleepingComputer reports that Anthropic disrupted several activities linked to the ShinyHunters data theft collective. An alleged French-speaking member using the handle frkoo ran a credential-harvesting pipeline across ten AWS EC2 workers. The pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app stores, decompiled them, and scanned them for hardcoded secrets with TruffleHog. Verified findings were routed in real time to a Telegram group organized into more than 100 source types. The same actor used a separate automated process to collect GitHub organization email addresses. The Associated Press, via SecurityWeek, reports that Claude users in northern Yemen, territory controlled by Iran-backed Houthi rebels, tried to develop advanced missiles. Anthropic blocked the accounts and said the users did not succeed in fielding an operational device but did carry out a failed test of a guided rocket. The company knows this because the users returned to the chatbot to ask why it failed. Anthropic did not identify the users. Hazam al-Assad, a member of the Houthis' political bureau, said it is unreasonable and illogical that the group would rely on open sources to develop military capabilities. The Hacker News reports the same document names seven China-based AI labs in industrial-scale distillation attacks against Claude.