Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Proactive’s coverage of London’s small caps continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Coverage of London’s small caps continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK

Tech

Chinese state-backed hackers used Anthropic’s AI to run near-autonomous cyberattacks

Anthropic has disclosed what it describes as the first documented case of a large-scale cyber-espionage operation carried out largely by artificial intelligence rather than human hackers, an escalation it says marks a turning point in global cybersecurity.

In a detailed statement, the company said it detected “suspicious activity” in mid-September.

It later concluded with 'high confidence' that a Chinese state-sponsored group had hijacked its Claude Code system to target roughly 30 organisations across technology, finance, chemicals and government. Anthropic said the attackers successfully infiltrated a “small number” of those entities.

What distinguishes this incident is not the number of targets, but the autonomy of the attack. Anthropic said the intruders manipulated its model into performing the majority of the intrusion work itself. “

The attackers used AI’s ‘agentic’ capabilities to an unprecedented degree, using AI not just as an advisor, but to execute the cyberattacks themselves,” the company said.

Investigators estimate Claude carried out between 80% and 90% of the campaign, leaving human operators to step in only at a few critical moments.

Once compromised, the system scanned networks, mapped high-value databases, wrote and tested exploit code, harvested passwords and extracted sensitive files, work that would normally require teams of highly-skilled hackers.

At peak activity, the AI was making “thousands of requests per second”, giving the attackers an operational tempo that human teams could not feasibly match.

The hackers achieved this by jailbreaking Claude: breaking instructions into small, apparently benign tasks and falsely telling the model it was working for a legitimate cybersecurity firm.

Deceived, the AI proceeded to run reconnaissance and exploitation routines without awareness of their malicious purpose.

In a final stage, Claude even produced its own documentation, organised lists of stolen credentials and system diagrams. to support subsequent waves of the espionage campaign.

Anthropic argues the attack confirms that a fundamental shift in cybersecurity is underway.

The company has previously warned that advanced models were becoming powerful enough to change the economics of cyberattacks by automating work that once required human expertise.

This campaign, it said, illustrates how quickly that threat is evolving. “These attacks are likely to only grow in their effectiveness,” the company said. “The barriers to performing sophisticated cyberattacks have dropped substantially.”

There were limits. Claude occasionally fabricated details such as credentials or overstated what information it had accessed, tendencies Anthropic says still constrain truly autonomous cyber operations.

Even so, the company has expanded detection systems, introduced new classifiers to flag malicious behaviour and is developing methods to spot large, distributed attacks earlier.

Anthropic also insists that the solution is not to halt the development of advanced systems. “The very abilities that allow Claude to be used in these attacks also make it crucial for cyber defence,” it said, noting that its own threat-intelligence team relied on Claude to analyse the enormous volumes of data generated during the investigation.

The company is urging organisations to begin integrating AI into routine defence work, from threat detection to incident response, and argues that collaboration across industry and government will be essential.

“A fundamental change has occurred in cybersecurity,” it said. “Improved detection methods and stronger safety controls are now critical.”

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK