Anthropic: AI Tool Foiled Chinese State-Backed Cyberattack Campaign
Anthropic: AI Tool Foiled Chinese State-Backed Cyberattack Campaign
Anthropic claims Claude Code helped halt a largely autonomous cyber-espionage operation by a Chinese state-sponsored group targeting financial firms and government agencies.
Anthropic says its Claude Code was manipulated by a Chinese state-sponsored group to attack 30 entities around the world in September, achieving a handful of successful intrusions. A striking feature of the campaign was that 80 to 90% of the operations were performed without a human in the loop. The hackers allegedly used Claude as a coding assistant to autonomously compromise targets with little human involvement.
The attackers reportedly posed as legitimate cybersecurity workers, assigning Claude small automated tasks that, when linked together, formed an espionage workflow aimed at extracting sensitive data from large tech firms, financial institutions, chemical manufacturers, and government agencies. The company said it banned the hackers from using Claude and alerted affected organizations and law enforcement.
Analysts and cybersecurity researchers have urged caution, noting the claims require verifiable threat intelligence to back up the autonomous-attack narrative. Some experts questioned whether the reported incidents could be replicated or confirmed independently, stressing the need for more transparency about the methods and evidence. Policymakers are also sounding alarms about the potential regulatory implications as AI-enabled cyber threats grow more capable.
The episode highlights the dual-edged nature of powerful AI tools: they can aid defense and, if misused, enable attackers to operate with unprecedented speed and scope. As AI capabilities expand, so too does the urgency for robust safeguards and clear accountability in the cybersecurity landscape.