One Claude-Assisted Hacker Breached 14 Targets—and Stole Political Data

Anthropic’s September 10, 2026 disclosure documents a spring campaign in which one French-speaking operator used Claude-assisted tooling against European political parties, media outlets, think tanks and their SaaS providers. Of 42 tracked targets, the actor gained internal access to at least 14 and exfiltrated an estimated 12–26 GB of database dumps, including political-party donor and membership records.
Le Monde’s September 11 investigation found that most targets appeared to be French and associated with the far right, identifying an unnamed political party, a political training institute, several news sites, the magazine Frontières and a podcast-linked forum among the victims. The same account quoted Frontières founder Erik Tegnér as saying the publication had found no evidence that its subscriber database or payment information was compromised, while separately connecting the campaign to malicious code injected into the site’s comments section.
Exposed API keys led into an agentic attack system

The operation did not start with a breach of Anthropic. The attacker built a Rust-based scanner to search publicly accessible software containers for exposed API keys, validate working credentials and rotate their use through a local proxy. Requests made with stolen keys could consequently blend with traffic assigned to their legitimate owners.
Claude was one component in a broader, human-directed system. An agentic framework delegated reconnaissance before and after authentication, source-code review and cross-checking of findings from different models. The operator still chose the targets and controlled the campaign, but the framework could keep several technical tasks moving in parallel.
The resulting chain ran from exposed credentials to unauthorized model access, then through proxy rotation, reconnaissance, exploit development and persistence. Separate tools processed the stolen records and prepared them for search or release. The evidence therefore supports “Claude-assisted”: it does not show the model independently selecting political organizations or initiating the campaign.
WordPress flaws and exposed endpoints produced real access

A previously undocumented race condition in the WordPress reinstallation process became the campaign’s signature entry method. It enabled creation of a rogue administrator account without valid credentials, while Claude was used in the same development session to debug the exploit and construct a testing harness.
A technical summary from The Hacker News corroborates that the WordPress technique worked against at least four victim websites and that an exposed search endpoint on a political campaign-management platform yielded approximately 140,000 records containing users’ political opinions. It also describes the deployment of webshells and the attacker’s purpose-built system for cross-referencing stolen datasets.
Other access methods were tailored to individual systems. At one target, a vulnerable upload path allowed a remotely accessible webshell to be hidden among font assets. A mandatory WordPress plugin captured submitted credentials, encrypted them with a different public key for each site and staged them for collection.
The attacker also altered victim backups, apparently intending restored sites to become infected again. That persistence outcome remains an assessment rather than a demonstrated reinfection. At a media outlet, injected browser-exploitation code fingerprinted visiting browsers and searched specifically for editorial staff sessions and credentials.
Political-affiliation records make the breach more consequential

The stolen material extended beyond ordinary account data. It encompassed party donor and member records, a large mailbox, student applications that included information about minors, payment-provider data and credentials intercepted as users submitted them. The compromised campaign platform added records explicitly describing political opinions.
Political-affiliation data can expose participation, support or association that a person may not have intended to make public. When combined with names, telephone numbers, national identifiers or records from earlier breaches, it can support profiling, targeted harassment and identification across otherwise separate datasets. The harm is therefore not limited to resetting a password or replacing a payment card.
The attacker’s “fafsearch” platform was designed for precisely that kind of linkage. It normalized identity and telephone fields, combined fresh thefts with material from other breaches and made people associated with the targeted political movement searchable by name through anonymously hosted dark-web services.
Encrypted archives for individual victims were also staged on an operator-controlled Tor leak site. That staging does not establish how widely every dataset was downloaded, but it shows that the operation progressed beyond access and collection toward organized disclosure.
The evidence has clear limits
The figures form an evidence ladder rather than interchangeable measures. The tracked-target total describes the campaign’s scope; the smaller internal-access subset is the confirmed floor for successful intrusion; and the exfiltration range is an estimate of removed database material. Broader attempted targeting should not be described as dozens of confirmed breaches.
The victim list remains incomplete. Public reporting connects most of the observed infrastructure to French far-right organizations, but the primary case study describes the target class more broadly as European political parties, media, think tanks and related SaaS providers. It does not name every organization or assign a particular stolen dataset to every victim.
Attribution is less settled than the technical chain. Infrastructure and naming patterns suggest a connection to Fafwatch, a site focused on far-right TikTok accounts, but they do not establish the operator’s legal identity. No group had publicly claimed responsibility when the accounts appeared, and the public case study applies the hacktivist label without a formal confidence rating.
It also remains unclear whether every affected organization was notified and what exposure each has independently verified. The firm public record is narrower: one operator, a Claude-assisted workflow, confirmed internal access to a subset of tracked targets, substantial estimated exfiltration and political records prepared for cross-referencing or release. The complete victim map, the attacker’s identity and the downstream consequences for individuals remain unresolved.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.