Site navigation

Anthropic: AI Automated Cyber Espionage Campaigns Are Here

Elizabeth Greenberg

,

ai automated cyber-attack
Anthropic says it detected what it believes to be “the first documented case of a large-scale cyber-attack executed without substantial human intervention.”

Anthropic, the creators of AI chatbot Claude, claim they have discovered the use of AI in a sophisticated espionage cyber campaign by a Chinese state-sponsored group.

The AI firm said that in September 2025, they detected suspicious activity which they later determined to be a highly sophisticated espionage campaign utilising AI’s agentic capabilities “to an unprecedented degree – using AI not just as an advisor, but to execute the cyber-attacks themselves.”

Anthropic said that the threat actor manipulated their Claud Code tool, using it to attempt to break into around 30 global targets, with a small amount of success.

Th campaign targeted government agencies, chemical manufacturing firms, financial institutions, and large tech companies.

“We believe this is the first documented case of a large-scale cyber-attack executed without substantial human intervention,” Anthropic said in a blog post announcing their finding.

While Anthropic went through the usual motions upon discovering the operation – notifying relevant authorities, blocking accounts – the revelation has major implications for the future of AI agents in cybersecurity.

Anthropic said that the operation relied on three main AI innovations – intelligence, agency, and tools – to operate at such a level.

The combination of AI’s increased intelligence for complex instructions and tasks, its ability to autonomiously operate, and its access to software tools, make it an increasingly volatile threat when used by threat actors.

In this case, threat actors were able to jailbreak Claud Code’s training which prohibits it from engaging in illegal or harmful behaviour. They accomplished this by breaking down illegal tasks into harmless, smaller tasks, while also ensuring the AI LLM that it was an employee of a real cybersecurity firm being used to test defences.

Attackers then used Claude to inspect the target organisation’s security systems, then using the LLM to test security vulnerabilities and eventually, steal credentials for further access to targeted systems.

Claude would also be used to document the attack, creating systemised files of the stolen credentials and the systems to help plan for future effective attacks.

Anthropic said that Claude was used for 80-90% of the entire cyber campaign, with only sporadic human intervention. While the chatbot did hallucinate on occasion, the effectiveness of its real-life application in cyber-crime is alarming.

Cyber leaders have warned that AI is dropping the barriers to sophisticated cyber-attacks since large language models hit the mainstream, but AI-driven cyber-attacks had long-been relegated to improving the effectiveness of social engineering tactics like phishing and pig butchering.

The prospect of an autonomously-run cyber espionage campaign that can target critical national infrastructure, large conglomerates, and nation-states alike is chilling.


Recommended reading


Anthropic says that this attack is an escalation on other advances in AI cyber-attacks it saw in the summer. For instance, vibe hacking still required a human in the loop – this new campaign required very little human intervention or leadership.

“This raises an important question: if AI models can be misused for cyberattacks at this scale, why continue to develop and release them?” Anthropic asked.

It answered its own question, claiming that Claude can be used in cyber defences, and saying that Claude was used by its own threat intelligence team in analysing this attack.

However, seeing that foundational models can face jailbreaking that allows them to create illegal and harmful content, it also raises the question on how AI is being regulated, and if AI developers will be held to account for the harmful material their machines produce.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data