A lone Francophone operator targeted 42 European political organisations in spring 2026 and gained internal access to at least 14 of them. He then built, on his own, a search engine allowing people affiliated with the targeted movement to be found by name, and published it on the dark web.

This case, referenced GTG-50029, is one of five linked to France or Francophone Africa in the report published on 10 September 2026 by Anthropic on malicious uses of Claude. The others describe a national surveillance platform in Mali, a Russian influence operation in Bangui, a network of fake media attributed to an agency based in France and a Francophone operator among ShinyHunters affiliates.

Anthropic does not name any victims. Le Monde, which examined the technical data published with the report, wrote on 11 September that they suggest the vast majority of targets in this case were French and linked to the far right. The newspaper identifies at least one political party, a political training institute, several news sites including the magazine Frontières, and a discussion forum linked to a podcast.

The report covers operations disrupted between December 2025 and August 2026, in seven areas ranging from hacking to surveillance and conventional weapons. Anthropic states that it selected the most notable and novel cases, not a representative sample of abuses. The accounts are based on its own investigations and its visibility of Claude usage. They therefore do not constitute independent confirmation of every harm, attribution or current state of the tools described. An operator's language is also not an attribution of nationality.

What the operator took

The targets were political parties, media, think tanks and the online software providers of these organisations. Anthropic estimates the exfiltrated data at between 12 and 26 GB: donor and member files of parties, a mailbox of 15,000 messages, student application files including data on minors, data from a payment provider. The encrypted archives were deposited, victim by victim, on a leak site accessible via Tor.

One access is treated separately in the report. The actor compromises a political campaign management platform through an exposed search endpoint, then instructs his agents to iterate on it. This yields approximately 140,000 records containing political opinions.

An exploit developed and debugged in a single session

The initial access technique is a race condition in WordPress reinstallation, previously undocumented, which creates an administrator account without valid credentials. Anthropic indicates that the operator developed and debugged it with Claude in a single session, including a test bench. It worked against at least four sites.

The rest of the tooling is of the same order. A scanner written in Rust detects and validates exposed API keys in public containers, then routes their usage through a local proxy layer. The attacker's traffic then blends with that of the legitimate key owner. A WordPress must-use extension, which runs on every page load and cannot be disabled from the dashboard, captures entered credentials, encrypts them with a site-specific public key and queues them for retrieval.

The actor also poisoned the backups of one of his victims. A restoration would have reinfected it.

One case directly concerns newsrooms. Against a media outlet, the operator deploys a browser compromise framework via a script injected into pages, and fingerprints several thousand readers' browsers. The report specifies what he was looking for: the sessions and credentials of the editorial team. According to Le Monde, these elements appear to match the attack suffered in the spring by the website of the magazine Frontières, through the injection of a spyware in its comment sections, a feature disabled since.

A doxxing engine built by a single person

The operation's signature tool is called fafsearch. Anthropic describes it as a doxxing platform: a compiled search engine, with ingestion pipelines, ability to cross-reference pre-existing leaks and exfiltrated data, normalisation of national identity and phone numbers, ranking logic, testing and containerised deployment.

Tens of millions of rows were loaded into it, including health identifiers and information from judicial system leaks, merged with the product of the actor's intrusions. The result was published as anonymously hosted services on the dark web. People affiliated with the targeted political movement could be searched by name.

Anthropic writes that it is "one of the clearest cases we have seen of AI-assisted software engineering applied directly to a mass attack on privacy", and that "the entire platform was created by a single person" (translated from English).

In Mali, a platform that banning does not stop

Case GTG-50027 poses a different problem. Anthropic attributes to a subscriber, likely an independent consultant based in Bamako, the development of Lakana 360 for the National State Security Agency. Claude served as the primary engineering force.

The platform monitors approximately 25 million SIM cards across the three national mobile operators. A low layer collects call records, messages and voice traffic. Above that come identification of the same user across SIM cards by voice fingerprint, flagging of encryption and VPN users, inference of clandestine meetings, geolocated watchlists and cross-referencing with the civil biometric registry. The protection of changing SIM cards falls away.

The sharpest point concerns the law. The module that produces an intelligence file on a given phone number initially required a judicial warrant. This requirement was removed at the operator's request, the component being reclassified as a national chain, control disabled by default and retention unlimited. The US State Department and Human Rights Watch have documented detentions and abductions of opponents, journalists and civil society members by Malian services.

Anthropic banned the account. The platform, however, runs entirely on-site with local models: measures taken on the account do not affect the deployed product. This is the operational limit that this case establishes. A provider can interrupt its model's assistance without being able to withdraw software already written and installed at a third party.

In Bangui, a safeguard bypassed by a change of vocabulary

Case GTG-04001 concerns a Russian-speaking operator in Bangui, whose account Anthropic says it deleted after a report from INPACT and the All Eyes on Wagner project. He fed daily content to Radio Lengo Songo, on 98.9 FM, in coordination with RT, Sputnik Africa, TASS and the Russian House in Bangui. An investigation by All Eyes on Wagner showed that the station was created and funded by the Wagner Group in 2017.

Anthropic's investigation links the operator to Politology, the influence branch of Africa Corps and Wagner, which it says came under the control of Russian foreign intelligence in late 2023. He would have been its local coordinator. The operation was entirely run from abroad while being built to appear Central African. The user explicitly asked Claude to incorporate pro-Russian and anti-French talking points, and to remove formatting tics so that news feeds would not read like generated text.

Claude refused the operation's most aggressive request, which was to designate real people as activists in order to provoke a security intervention against them. The model also flagged the political weighting of staff evaluation grids, which the operator had it draft with contracts imposing loyalty to the Central African president and to "Russia and its contingent". It was enough to rephrase the criteria in neutral terms to retain the scoring.

Anthropic classifies the dissemination at the fourth level of the Brookings scale, which has six, due to daily radio broadcasting and reposts on Telegram and in local media. This classification describes the channels reached. It does not measure public adherence or political effect.

A French agency behind 70 fake media

Case GTG-54002 is described as a commercial influence-for-hire operation. Anthropic links it to LKM Company, a digital advertising agency based in France. The network published at least 8,913 articles in about twenty languages on approximately 70 fake news sites, relayed by as many matching X accounts and by more than 250 inauthentic comment accounts.

The network defended no political line. It changed position according to the client of the moment, which corresponds to a commercial influence-for-hire model. The domains were registered from France in a ten-week window in mid-2025, hosted on shared infrastructure behind a single deployment. This is what allowed investigators to link the 70 sites to a single account.

The target audiences were the United States, Brazil, France and the Democratic Republic of the Congo. The latter country accounts for 318 articles. Anthropic says it found signals suggesting the interest of one or more clients with a stake in the conflict between the DRC and Rwanda, without being able to confirm who commissioned these contents, and without finding evidence of government direction.

The company classifies the operation at the second level of the Brookings scale: dissemination remained largely confined to its own sites and accounts, with little observable engagement from real audiences. The number of articles published therefore does not measure influence.

Stolen AI keys to fund the next attacks

The fifth case, GTG-50014, groups operators that Anthropic suspects of being affiliated with ShinyHunters. One of them, Francophone, uses the aliases MeowSHA, frkoo and blazespider.

His credential collection setup ran on a fleet of ten EC2 instances: bulk download of 1.8 million Android application files, decompilation, search for hardcoded secrets, and routing of verified findings to a Telegram group organised into more than one hundred source types. He operated a shop of stolen banking data under the domain policenationale[.]cc. Anthropic interprets this name as the criminal service's brand rather than as a phishing lure.

The operations grouped in this case are not all attributable to this single operator. They include the theft of more than one terabyte from a technology provider, access to systems containing tens of millions of passenger records at an airline, and a session dump covering more than 2,100 sets of Azure AD tokens spread across more than 40 enterprise tenants, in about 34 hours.

Another mechanism is of more direct interest to businesses. In several intrusions, attackers stole the victim's AI API keys from their own software providers, then switched their offensive workloads to these keys. One of them was used for about three weeks to attack other organisations. Anthropic specifies that these keys came from its customers' environments and that its own systems were not compromised.

Operators gain three things at once, according to the report: resale of keys, compute billed to someone else, and activity attributed to the legitimate owner.

What these cases impose on French organisations

A practical conclusion runs through the five cases. Initial accesses remain classic: exposed keys, stolen credentials, unpatched component. What AI adds is speed, scope and data processing capacity once inside. An AI API key must therefore be treated as a production credential, because that is how attackers treat it.

The Bangui case adds a lesson on safeguards. The categorical refusal held on the most serious request. Rephrasing in neutral terms was enough on the intermediate request. A control that focuses on wording gives way before an operator who learns to rephrase.

One question remains that the report leaves open: the list of victims and informed authorities, case by case. Anthropic indicates that it shared intelligence with authorities and industry partners "where appropriate", without further detail.

Yet the donor and member files described in case GTG-50029 reveal political opinions, a special category under the European regulation. As the CNIL (France's data protection authority) reminds, the data controller must notify the competent authority, if possible within 72 hours of becoming aware of the breach, and inform the data subjects when the risk is high for their rights and freedoms. The processor, for its part, must alert the controller without undue delay. An organisation among the 42 entities followed has, from reading the report, no way of knowing whether it is one of the 14.

Our articles will then appear first in Google Top Stories.