One hacker doxxed the French far right with Claude
A lone hacktivist used Claude to file the French far right, and Le Monde has now named the targets one by one. The barrier to entry is gone.
Five days ago, I wrote that my kids turned up in the French education ministry's data leak, scraped by an organized crew. The same Anthropic report that just detailed how seven Chinese labs copied Claude tells another story, quieter and the one that got to me more, because it no longer needs an organized crew. In the spring of 2026, a single French-speaking person broke into fourteen parties and outlets, mostly the French far right as it turned out, and built themselves an engine to file the whole movement[1][2]. Not a team, not a state, one person and an assistant.

One person, forty-two targets
The report files this actor under the tag GTG-50029 and describes them plainly, a French-speaking hacktivist who went after parties, media outlets, think tanks, and the providers that host them[1:1]. A hacktivist is a hacker who acts for a cause rather than for money, and this one had theirs. Out of forty-two organizations under watch, they got inside at least fourteen, a tally the report would have pinned a year ago on an intelligence service, not on one person[1:2].
The method is the reason. The actor wrote themselves a Rust scanner, with Claude, to spot access keys[3] left in the open inside public containers, then ran them behind a relay that blended their traffic with the key owner's, so nothing stuck out[1:3]. They ran sub-agents, the secondary assistants a main one spins up and coordinates, one for reconnaissance, one to review code, a third to check another model's findings[1:4]. Their signature move was a fresh flaw in WordPress, the software behind a large share of the web, a race between two reinstall operations that minted an administrator account with no password, written and debugged in the same session as the attack, and good against at least four sites[1:5]. Against a political campaign platform, they used a search endpoint left open to exfiltrate roughly 140,000 records holding people's political opinions[1:6]. Elsewhere, they booby-trapped a news outlet's readers with an attack framework that hooked their browsers, to fingerprint thousands of visitors and hunt for the newsroom's own credentials[1:7].
The report names no target, but Le Monde and Euronews needed about a day to place them, mostly in France and on the far right, at least one party whose member list walked out the door, a political training institute, several news sites, and a forum attached to a podcast[2:1]. The outlet with the booby-trapped readers appears to be the magazine Frontières, which owned up to a tracker slipped into its comments section this spring, since switched off, and whose founder Erik Tegnér told Le Monde nothing shows its subscribers or their payments were touched[2:2]. As for the others, nobody even knows whether they were told[4], and since the education ministry leak I know what that silence does to the people inside it.
Fafsearch, an engine to file people
The centerpiece has a name, fafsearch, and the name is worth a pause. "Faf" is French slang for a far-right militant, so the tool announces its target, a far-right movement the report is careful not to name[1:8]. The actor built a compiled search engine with Claude, with its ingestion pipelines, its ability to cross-reference one breach against another, its normalization of ID and phone numbers, its ranking logic, and a ready-to-run deployment[1:9]. They loaded it with tens of millions of rows, including national health identifiers and data pulled from justice-system breaches, then published it as hidden services on the dark web, where anyone affiliated with the targeted movement could be looked up by name[1:10]. No one has claimed the attacks, but Le Monde ties the suspect to Fafwatch, a site that catalogs far-right TikTok accounts and is said to be close to anarchist circles[2:3].
This, Anthropic writes, is one of the clearest cases it has seen of AI-assisted software engineering aimed straight at a mass attack on privacy, and one person did all of it[1:11]. In total the actor exfiltrated 12 to 26 gigabytes, party donor and member files, a 15,000-message mailbox, application records holding minors' data, payment-provider information[1:12].
Whether you approve of the filed movement or not changes nothing here, and saying so is the whole point. An engine that sorts citizens by their opinions and spits out their health identifiers picks no side, it obeys whoever holds it. Today it aims at a far-right group, tomorrow at a union, a parish, or a neighborhood association, same code, same ease. That isn't a thought experiment either, since in May a platform run by La France insoumise, the main party of the French left, was targeted in turn, with no established link to this case, and the party took it to the CNIL, France's data-protection authority, and filed a complaint[4:1]. The technique doesn't care about the cause it serves, and that is exactly what makes it dangerous.
Security through obscurity is finished
This hacktivist isn't the only one in the report with a French accent. A French-speaking operator tied to the ShinyHunters collective, known for data thefts followed by extortion, decompiled 1.8 million Android apps hunting for secrets and ran a stolen-card shop behind a site dressed up as the French national police, fed by a 400,000-row file from a French telecom, IBANs included[1:13]. A French advertising agency, for its part, ran seventy fake news sites and close to 9,000 articles in about twenty languages[1:14]. Three French cases in one document, and a common thread Anthropic sums up in a line, sophisticated attacks no longer require sophisticated attackers[1:15].
That thread lands, because I see from the other side what makes these attacks work. In my job as a project manager, I've run into secrets in plain text in code more than once, an API key left in a public repo, the kind of slip that opens a door. The good news is that it gets fixed, and that GitHub, the largest code host in the world, finally rolled out bots that catch these keys the moment you publish them[5]. The bad news is elsewhere, in everything still running with no one watching it, because whoever ran it left and no one was told to take over, all the more since taking over is thankless when nothing is documented. Those systems don't get fixed, they wait. "Security through obscurity is no longer viable," the report writes, and a server everyone forgot because it interested no one becomes, under a model that reads an obscure configuration in seconds, a target like any other[1:16].
What it changes from here
I asked myself whether my own agents could go off the rails like that, and the honest answer is no, because they've never stepped past their instructions. The difference isn't in the tool, it's in the intent of whoever holds it. The same assistant that helps me stand up a prototype helped this man file a movement, and nothing in the machine tells the two uses apart before it's too late, except the safeguards Anthropic closes after the fact by banning the accounts.
What changed is the price of entry. Yesterday it took a team, months, and rare know-how to sustain a campaign against fourteen organizations; today it takes a motivated person and a subscription. CyberScoop sums up the moment by saying AI lets small actors run state-level campaigns[6], and that runs both ways, since the same shift that arms an intelligence service also arms the individual against it. I watch my kids show up in a leak on Monday and one man build a political blacklist on Tuesday, and I figure the question is no longer who can afford it. Everyone can now, and that's what worries me.
Notes
Anthropic, "Detecting and countering misuse of AI: September 2026" (PDF), September 10, 2026. The hacktivist GTG-50029 runs from page 34 to 38, the ShinyHunters operator on pages 12 and 13, the advertising agency on pages 47 and 48. The landing page carries the gist. ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎
Le Monde, "Anthropic reveals hacker used Claude to target French far-right organizations", September 11, 2026. ↩︎ ↩︎ ↩︎ ↩︎
An access key, or API key, is a password that opens a service to a program rather than to a person. Left in public code, it hands whoever finds it the owner's rights. ↩︎
Midi Libre, "À l'aide de l'IA Claude, un hacker pirate des organisations d'extrême droite françaises et leur vole des milliers de données" (in French), September 11, 2026. ↩︎ ↩︎
GitHub, "Secret scanning and push protection are enabled by default on new public repositories", March 11, 2024. The block covers recent public repos on personal accounts, not the ones that already existed. ↩︎
CyberScoop, "AI lets small actors run state-level hacking campaigns, Anthropic report finds", September 10, 2026. ↩︎