A recent threat intelligence report from Anthropic, a company known for its work in artificial intelligence, reveals how cybercriminals and influence operations are using generative AI tools to conduct attacks in France and other Francophone regions. The report outlines various incidents involving data theft, impersonation of official institutions, and the spread of disinformation. These activities highlight the growing use of AI in cybercrime and political manipulation.
One example involves a cybercriminal known as frkoo, who goes by other names such as MeowSHA and blazespider. frkoo is part of a group called ShinyHunters and has been involved in extracting sensitive information from Android apps. This operation involved decompiling over 1.8 million apps and transmitting the extracted data to Telegram groups, which were organized into more than 100 categories. The attacker also used a network of 10 servers on Amazon Web Services to collect and process this information.
In one attack, stolen AI API keys were used to gain control of a major French retail chain's cloud infrastructure. The hacker was able to move from a stolen developer token to full administrative access in just three hours. AI agents were used to explore the network quickly, identify vulnerabilities, and extract sensitive data. One of the stolen keys was later used for three weeks to launch further attacks on other organizations.
To sell the stolen data, frkoo created a website that impersonated the French National Police. The site, named policenationale.cc, served as a storefront for stolen credit card information. It also included access to pirated databases containing personal financial details of over 400,000 customers of a French telecom provider. These domains were used to automate the sale of stolen data, acting as a centralized platform for various data leaks.
Anthropic also uncovered a network of fake news sites operated by LKM Company, a French digital advertising agency. Over 10 weeks in mid-2025, the company created around 70 fake news sites, including Naija Pulse and Echo Berlin, to spread content across six continents. The AI model Claude was used to generate or rewrite articles in a specific format, mimicking legitimate news sources. Despite being designed to appear independent, the network was traced back to LKM, with a focus on regions such as the Democratic Republic of Congo, where they published articles about mining and regional conflicts.
In 2026, a Francophone hacktivist used AI to attack European political groups, media, and think tanks. The attacker used a server from the French provider Scaleway to develop a new exploit for WordPress in a single session, allowing them to steal 140,000 records of citizens’ political views. Additionally, a Russian-speaking operator linked to Russian intelligence services managed a radio station in the Central African Republic, using AI to generate content that promoted pro-Russian and anti-French messages.
Cybercriminals and Influence Operations in France and Francophone Regions Utilize Generative AI
AI-rewritten from original reportingHow it works
aicybercrimefrancedisinformationdata-theftinfluence-operations



