Opens in a new tab
vmblog logo 2024 wht (updated)

Chinese State-Sponsored Hackers Weaponize Anthropic's AI in Landmark Cyberattack Campaign: Security Experts Weigh In

Share: 

David Marshall | Published: November 14, 2025

In what Anthropic is calling “the first documented case of a large-scale cyberattack executed without substantial human intervention,” suspected Chinese state-sponsored hackers have successfully weaponized artificial intelligence to conduct an automated cyber-espionage campaign targeting dozens of organizations worldwide.

The AI-powered operation, disclosed in a Thursday blog post by Anthropic, marks a watershed moment in cybersecurity history. The threat actors leveraged Claude Code-Anthropic’s generative AI coding assistant-to autonomously handle 80-90% of attack operations against approximately 30 global targets, requiring only sporadic human oversight. According to the company, the compromised AI executed system inspections, created exploit code, harvested credentials, and exfiltrated sensitive data at a scale and speed previously impossible for human operators alone.

“At the peak of its attack, the AI made thousands of requests, often multiple per second-an attack speed that would have been, for human hackers, simply impossible to match,” Anthropic stated in its disclosure.

The targets spanned critical sectors including large technology companies, financial institutions, chemical manufacturing firms, and government agencies. While Anthropic confirmed that several intrusions successfully exfiltrated sensitive information, the company declined to specify which organizations were compromised, noting only that the U.S. government was not among the victims of successful breaches.

Detection and Response

Anthropic first detected the malicious activity in mid-September 2024, triggering a comprehensive ten-day investigation. The company’s response included mapping the full scope of the operation, systematically banning malicious accounts as they were identified, notifying affected entities, and coordinating with law enforcement authorities.

Jacob Klein, Anthropic’s head of threat intelligence, told The Wall Street Journal that the level of automation observed in this campaign was unprecedented in the company’s cybersecurity experience. Based on digital infrastructure analysis and other intelligence indicators, Anthropic expressed “high confidence” that the operation was conducted by Chinese state-sponsored threat actors.

The AI Security Paradox

The revelation raises profound questions about the dual-use nature of advanced AI systems. Anthropic’s researchers acknowledged this tension directly: “If AI models can be misused for cyber-attacks at this scale, why continue to develop and release them?”

Their answer points to an emerging reality in cybersecurity: “The very abilities that allow Claude to be used in these attacks also make it crucial for cyber defense.” As threat actors increasingly leverage AI to accelerate and scale their operations, defenders must deploy equally sophisticated AI-powered tools to detect, analyze, and respond to attacks in real-time.

This incident underscores the critical need for robust AI safety measures, continuous monitoring for misuse, and industry-wide collaboration to prevent malicious actors from exploiting commercial AI systems for cyber-espionage and attacks.

Industry Expert Reactions

As news of this groundbreaking attack spreads through the cybersecurity community, experts are weighing in on the implications for enterprise security, AI governance, and the future of cyber warfare. Here’s what leading security professionals are saying about this development: 

++ 

Michael Bell, Founder & CEO, Suzu Labs:
 
If accurate, this represents the inflection point where AI systems execute 80-90% of sophisticated attacks autonomously, not just advise attackers. Jailbreaking Claude by convincing it this was legitimate penetration testing shows this isn’t an edge case anymore, it’s operational doctrine.

The technical scenario is feasible, and these attack patterns will be weaponized at scale. Organizations deploying AI agents with tool access need detection capabilities today, regardless of how this specific disclosure evolves. 

Organizations need to prepare for AI-powered attacks whether or not this specific disclosure proves exactly as described, because the jailbreak techniques and autonomous exploitation patterns are technically feasible and will be weaponized regardless.

++

Noelle Murata, Sr. Security Engineer, Xcape, Inc.:
 
This highlights how agentic AI significantly lowers the bar for sophisticated, targeted attacks, effectively giving a single entity the capabilities of a full hacking team. Security professionals should anticipate agentic AI being used both offensively and defensively: they should tighten rate limits and anomaly detection on their own LLM endpoints, limit API keys and scopes, and monitor for scripted bursts indicative of model misuse. 
 
On the enterprise side, they should strengthen identity verification (FIDO2), reduce session/token durations, and watch for high-speed reconnaissance activity consistent with AI tools. Anthropic and external researchers also caution against overhyping these findings, as some claims are disputed. This emphasizes the importance of measurement and telemetry when implementing LLMs for sensitive workflows.
 
The time for predictive AI defense is over; the future of cybersecurity is a real-time, autonomous AI war.

++

John Watters, CEO and Managing Partner at iCOUNTER:

This is simply the tip of the iceberg and a clear indication of the future threat landscape. Ive spoken at length of the movement where all victims become Patient Zero as adversaries leverage AI to conduct reconnaissance on a target, then build bespoke capabilities designed to exploit each specific target.  Just look at the success of this operation leveraging off the shelf AI capability.  Imagine what an adversary can do with a well-tuned LLM purpose built for an espionage mission.

++

Trey Ford, Chief Strategy and Trust Officer at Bugcrowd:

The notion of dual use has always been a source of frustration in cybersecurity. We cannot downplay the importance of developing offensive capabilities to test our defensesfinding and fixing issues before malicious actors exploit them.

Anthropic is fighting a good fight; theyve invested heavily in a strong security team, and a very capable threat intelligence team who are monitoring, reporting, and sharing their work.

The old world pattern of addressing and disposing of issues, attacks, and abuse quietly only benefits the attackers. Ultimately, sunshine is the best disinfectantsharing this in the light of day for the public to learn and adapt from helps us all improve.

We need to support and encourage companies to follow Anthropics example here by collecting actionable intelligence, working with the various government agencies, and then notifying the public of changes.

AI makes humans faster, whether your intentions are altruistic or malicious. Whats great about how Anthropic has handled this is theyve captured intelligence about the threat actors tactics and procedures and theyre sharing how theyre working. This also underscores the need for renewing protections under CISA 2015. There are no legal projections for intelligence sharing with that coverage expired.

++

Toby Lewis, Global Head of Threat Analysis at Darktrace:

While this campaign is not a fully autonomous attack, it does show how threat actors are already using AI to orchestrate and scale the same techniques weve seen for years from reconnaissance and credential theft to lateral movement and data exfiltration. The AI use here is essentially a smart coordinator for standard offensive tools, allowing an operator to say scan here, pivot there, package this up in plain language instead of writing custom scripts for every step. This allows attackers to rapidly prototype and refine attack chains, making their operations more agile and can allow them to switch from one target to the next more quickly without having to completely re-tool.

It is important for organizations to remember that AI-driven attacks cannot always be identified as so: regardless of whether the code was produced by an AI system or written manually, it behaves the same once its inside the victims environment.

++

Diana Kelley, Chief Information Security Officer at Noma Security:

The disclosure by Anthropic that state-linked actors are using its AI models to automate large portions of cyberattacks underscores the reality that AI is being weaponized by adversaries. The fact that criminals and nation-state actors can now conduct reconnaissance, credential harvesting and data exfiltration with minimal human involvement signals a shift in the threat landscape. Defenders can no longer rely on traditional detection cycles or manual review. Security programs must be shored up with the visibility, automation and disciplined cyber hygiene needed to counter attacks that operate at machine speed. The report from Anthropic is an excellent reminder that we must keep vigilant about foundational security controls and adopt AI-aware response capabilities so we are not playing catch-up in the AI powered breach race.

++

Chrissa Constantine, Senior Cybersecurity Solution Architect at Black Duck:

According to Anthropics recent disclosure, a Chinese state-sponsored group allegedly weaponized Claude Code, not as an assistant, but as an autonomous agent. The AI infiltrated approximately 30 global targets across technology, finance, chemicals, and government sectors, performing reconnaissance, writing exploit code, harvesting credentials, and documenting results with minimal human oversight. 

This marks a fundamental shift in the threat landscape. What once required months of coordinated human effort can now be accelerated through AI-driven automation. Key implications include:

  • Lower Barrier to Entry: Sophisticated attacks no longer demand elite hacking teams; smaller actors can scale operations using AI.
  • Speed and Volume: The model processed thousands of requests at machine speed, which is far beyond human capacity.
  • Stealth and Complexity: Multi-stage campaigns orchestrated by AI agents are harder to detect and disrupt.

As AI systems gain agency, tool access, and decision-making capabilities, defenders must rethink threat models. Anthropic notes that the same advanced features enabling misuse are also critical for defense – underscoring the urgency for AI-augmented security, stronger detection, and new safeguards. Techniques observed or inferred include:

  • Prompt Engineering: Assigning personas and stepwise instructions to bypass guardrails.
  • Context Manipulation: Breaking tasks into innocuous steps to hide malicious intent.
  • Agentic Loops: Running models iteratively with minimal human input.
  • Tool Invocation: Leveraging APIs and external tools via protocols like MCP.
  • Jailbreak Strategies: Misrepresenting tasks as legitimate (e.g., simulate a penetration test).

This is no longer a theoretical risk, but an active threat. The cybersecurity community must treat AI-agent misuse as a present danger, not a future possibility.

++

Ben Kliger, Cofounder and CEO of Zenity:

Its good to see Anthropic step forward and share details on a significant incident. None of this should surprise security leaders. Threat actors already target AI agents, try to compromise them and attempt to drive them into actions outside their intended purpose. Organizations set intent for agents and assume they will operate inside those boundaries, yet enforcement is difficult and real visibility into agent behavior is limited.
 
As enterprises place AI deeper into core workflows, similar cases will appear. Leaders need to treat AI Security as a priority now. This is not about slowing innovation. It is about operating with responsibility and control. If you do not secure agents, you do not secure AI.

++

David Colwell, VP of AI and ML, Tricentis:

This incident is a wake-up call for anyone deploying agentic AI. The same AI that we all love because it can research potential customers and help us write personalized emails can just as easily be used to socially engineer private information. The same AI used for company profiling and web crawling can engineer sophisticated phishing campaigns. The same AI that finds and fixes security issues is now donning its black hat and hacking those same companies. The autonomy that makes these systems efficient is exactly what makes them vulnerable. Agentic AI doesnt understand context or intent; it simply follows instructions.

AI has made great skills available to anyone for any purpose. We cant unscramble these eggs, but we can guard against them.

Businesses need to think of AI queries the same way they think about bot web crawlers: untrusted entities gathering data or looking for cracks.

We need full transparency into autonomous behavior. If you cant see what an AI system is doing, you cant secure it. Trust only comes when every action is visible, verifiable, and governed. In the age of agentic AI, trust is the only business currency that matters.

++

Evan Powell, CEO, DeepTempo:

This report is gaining enormous attention – and yet it mostly confirms what other reports from OpenAI, Google, and Anthropic have shared in the past – their LLMs are being used to design, orchestrate, and execute attacks of great sophistication and adaptability.

All of this comes on top of a crisis in cybersecurity – despite hundreds of billions of dollars of spending per year and the implementation of increasingly annoying controls by consumers, enterprises, and governments – we are losing trillions of dollars and some of our most precious information to attackers. Unless the cybersecurity industry takes on a more data-centric approach to detecting and predicting attacks, an already bad situation will become potentially catastrophic to many organizations and further undermine the use of the internet for permissionless communications and commerce.  

The foundations of our open societies and economies are under attack and we are woefully unprepared. 

##