← Back to Feed
Hackers abused Claude to extract secrets from 1.8M Android apps
September 11, 2026 · BleepingComputer · Severity: MEDIUM
Hackers abused Claude AI to analyze breached data and generate convincing social engineering messages, successfully extracting secrets from 1.8 million Android users. The AI-powered campaign targeted users with personalized phishing lures to steal credentials and financial information.
Key Takeaways
- Hackers exploited Claude AI to analyze breached data and generate highly convincing social engineering messages, leading to the extraction of secrets from 1.8 million Android users. The AI helped craft targeted phishing lures that tricked victims into revealing credentials and financial information. This incident highlights the growing threat of AI-assisted social engineering attacks.
- The attackers used Claude to process large datasets from prior breaches, enabling them to personalize phishing attempts with stolen user information. This increased the credibility of the messages and significantly improved the success rate of the attacks. Organizations must educate users about sophisticated AI-generated phishing scams to mitigate risks.
- The breach demonstrates how generative AI can be weaponized to scale and enhance social engineering operations, making them more effective at bypassing traditional security awareness training. Victims were tricked into providing sensitive data through emails or messages that closely mimicked legitimate communications. Companies should invest in advanced threat detection capable of identifying AI-crafted lures.