Some experts question Anthropic's claims of cyberattack breakthroughs using its tools, noting that white-hat hackers report modest gains from AI-aided hacking
Researchers from Anthropic said they recently observed the “first reported AI-orchestrated cyber espionage campaign” …
Ars Technica Dan Goodin
Context & Ripple Effects
Anthropic’s claim of an AI-orchestrated espionage campaign sits alongside its earlier report that Claude had been weaponized for sophisticated cybercrime, including data extortion, in its August threat-intelligence findings. This article matters because it tests whether those reports demonstrate a step-change in offensive capability or primarily faster assistance within existing workflows.
The related coverage shows the debate moving from claimed misuse toward more concrete technical milestones, including Google TIG’s report of AI being used to discover and weaponize a zero-day in a reported zero-day case. The distinction between orchestration and modest productivity gains is central to assessing the actual security exposure.
First-order effects
- Anthropic’s characterization of its observed activity faces immediate credibility scrutiny, while white-hat practitioners’ reports of modest gains temper the claim that AI has already transformed hacking capability.
- Security teams and policymakers have less basis to treat broad “AI-orchestrated” labels as evidence of autonomous offensive breakthroughs without clearer technical detail.
Second-order effects
- AI labs and threat-intelligence vendors face pressure to separate tool-assisted misuse from genuinely agentic operations in their public reporting, since those categories imply different defensive priorities.
- Defenders may prioritize controls around AI-assisted reconnaissance, code generation, and campaign coordination rather than redesigning their posture around fully autonomous attackers.
Third-order effects
- If reporting continues to mix incremental assistance with autonomous operations, cyber-risk governance could be shaped as much by contested capability narratives as by demonstrated incidents.
- The more durable shift is toward evidence-based dual-use AI oversight: institutions will need shared definitions and incident disclosures that distinguish capability claims from operational proof.
The trend: This is one data point in the move from generic fears of AI-enabled hacking toward contested, evidence-driven measurement of how much autonomy AI adds to real cyber operations.
Related: Dual-use AI governance · Agentic attack surface · Anthropic report on Claude cybercrime misuse · Google TIG report on AI-discovered zero-days · AI use in the cyber cat-and-mouse game
Related Coverage
- China's ‘autonomous’ AI-powered hacking campaign still required a ton of human work CyberScoop · Derek B. Johnson
- No, AI Is Not Yet an Unstoppable Security Threat This Week in Tom Merritt · Tom Merritt
- Chinese Hackers Trick Anthropic's AI into Automating Their Cyberattacks Breitbart · Lucas Nolan
- AI's Dark Dawn: Chinese Hackers Unleash Autonomous Cyber Onslaught on Global Targets WebProNews · Dave Ritchie
- Security News This Week: A Major Leak Spills a Chinese Hacking Contractor's Tools and Targets Wired
- Anthropic claims of Claude AI-automated cyberattacks met with doubt BleepingComputer · Bill Toulas
- Anthropic: Chinese AI hackers are after you! Security researchers call BS Pivot to AI · David Gerard
- AI firm claims Chinese spies used its tech to automate cyber attacks BBC · Joe Tidy
- Anthropic Exposes First Large-Scale Cyberattack Powered by AI Automation Unite.AI · Alex McFarland
- AI Ran Its First Autonomous Cyberattack The Power Law · Peter Wildeford
- Anthropic says an AI may have just attempted the first truly autonomous cyberattack Fast Company · Taylor Hatmaker
- Anthropic's AI was used by Chinese hackers to run a Cyberattack Engadget · Matt Tate
- Anthropic Says Its AI Chatbot Was Used By Chinese Hackers for Large-Scale Cyber Attack SFist · Jay Barmann
- AI firm claims it stopped Chinese state-sponsored cyber-attack campaign The Guardian · Aisha Down
- State-sponsored Chinese hackers used American AI technology to carry out cybercrimes: Anthropic Washington Examiner · David Zimmermann
- Hackers Told Claude They Were Just Conducting a Test to Trick It Into Conducting Real Cybercrimes Futurism · Victor Tangermann
- Anthropic says Chinese hackers used AI tool to conduct cyberattack The Hill · Julia Shapero
- Spotting cybercrime as marketing material works for Anthropic Semafor · Rachyl Jones
- AI System Abused in China-Linked Cyberattack, Says Anthropic CircleID
- Security Analysts Skeptical That Claude Code Really Hacked 30 Orgs on Its Own PCMag · Jon Martindale
- Anthropic warns state-linked actor abused its AI tool in sophisticated espionage campaign Cybersecurity Dive · David Jones
- Hackers (with a little help from Claude) launch one-click cyberattacks KnowTechie · Ronil Thakkar
- Anthropic warns of AI-driven hacking campaign linked to China Daily News
- I'm reading this piece about the AI-orchestrated attack using Anthropic, and what really jumps out at me is this: the fundamentals still matter just as much as they always have. … Matt McKenney
- We've reached a cybersecurity inflection point: sophisticated AI agents are no longer just theoretical - they're being weaponised. … Jagadeesh Kovi
- Fully autonomous hacking with MCPs and AI! — Anthropic came out with a mega story this week. On the other side, Ars Technica offers … Ariel Pisetzky
- Best quote I've seen all day so far, from an Ars piece by @dangoodin on skepticism around OpenAI's breathless claim that a Chinese hacking group used Claude code to automate 90 percent of their attack: … @briankrebs@infosec.exchange · BrianKrebs
- I could really benefit from experts' analysis of this WSJ article reporting that China-backed hackers used Anthropic's Claude to automate 80% to 90% of a September hacking campaign targeting corporations and governments. — There aren't a lot of specifics, but among those provided: … @dangoodin@infosec.exchange · Dan Goodin
- Anthropic's AI cyberespionage report feels as odd as the last one. Just 13 pages, it has none of the traditional components of a usual threat intel report (IoCs, payload hashes, TTPs etc.) and it seems to bury the lead re: technical sophistication. … @jkirk@infosec.exchange · Jeremy Kirk
- I agree with Jeremy Kirk's assessment of the Anthropic's GenAI report. It's odd. Their prior one was, too. — The operational impact should likely be zero - existing detections will work for open source tooling, most likely. The complete lack of IoCs again strongly suggests they don't want to be called out over that. … @GossiTheDog@cyberplace.social · Kevin Beaumont
- Disrupting the first reported AI-orchestrated cyber espionage campaign Hacker News
Discussion
-
Vox
Joshua Keating
on x
The age of AI-run cyberattacks has begun
-
@chrismurphyct
Chris Murphy
on x
Guys wake the f up. This is going to destroy us - sooner than we think - if we don't make AI regulation a national priority tomorrow.
-
@uk_daniel_card
@uk_daniel_card
on x
What the f is this guy on about 😆😆😆😆😆😆😆😆😆😆 This Anthropic thing is marketing guff. AI is a super boost but it's not skynet, it doesn't think, it's not actually artificial intelligence (that's a marketing thing people came up with). For every attack there's a defence.
-
@jeremyphoward
Jeremy Howard
on x
Looks like the lobbying for regulatory capture to ensure lock-in of profits to the private sector is working. :(
-
@theahmadosman
Ahmad
on x
a reminder that Anthropic is a > fear-mongering company thatʼs > lobbying against opensource AI > to stop you from running > your own AI models theyʼre > pro-regulation with an agenda > pushing “safety” as control > wants to gatekeep, not protect > malicious DO NOT TRUST THEM [im…
-
@lior_eth
Lior Messika
on x
Chris, the alarmist nature of this post shows the dramatic dissonance between *fear* and *understanding* of the goings on in this space by lawmakers and politicians (this isn't a dig at you personally at all). This is exactly what Anthropic wanted to incite with this blog, and
-
@suchenzang
Susan Zhang
on x
ylc might finally be back on his rockers! good sign, good take. 🫡
-
@kathleen_tyson_
Kathleen Tyson
on x
Claude calls BS on Anthropocene: “This pattern—detailed technical reporting combined with evidence-free geopolitical attribution—is unfortunately common in Western cybersecurity reporting and should raise serious questions about the reliability of such claims.”
-
@siddsax
Siddhartha Saxena
on x
Often don't agree with @ylecun, but the closed‑source rhetoric of @AnthropicAI does not sit well with me. Cybersecurity became a field because computers started running things. We didn't regulate computers out of existence, saying only a select few could build them with
-
@vraserx
@vraserx
on x
I'm with Yann on this one. A lot of these doom-sounding “studies” feel less like science and more like lobbying. If we let fear run the show, open models will get smothered by regulation tailor-made for the biggest players. [image]
-
@cesarcer
Cesar Cerrudo
on x
This report seems it was written by the marketing team to position Anthropic as the most advanced AI for cyber security, great marketing stunt but with real implications
-
@icesolst
@icesolst
on x
God dammit CEO just asked what we're doing about Chinese AI autonomous hacking, fuck you anthropic and your marketing posts
-
@pmddomingos
Pedro Domingos
on x
Anthropic, which calls itself an AI safety company, bragging about how unsafe its product is.
-
@theemozilla
@theemozilla
on x
Yann correctly calling out the tried and true playbook of “look at this scary thing! trust me you should be scared of it! and of course I am the only one who can protect you from it!”
-
@jsevillamol
Jaime Sevilla
on x
Some commentary by cyber sec experts on the Anthropic report. My impression is that the attack itself is being oversold — they likely got some private emails of target executives, and summarized some personal info about them? [image]
-
@f_j_j_
Francis Jervis
on x
Feels off. If they're so sure it's a Chinese state-linked actor, post receipts. Seems implausible a putative state actor would risk exposure for a “vibe hacking 2.0” op (vs using domestic/OSS tools) *and* apparently have really bad (in some undisclosed way) opsec.
-
@rnaudbertrand
Arnaud Bertrand
on x
Don't fall for the obvious propaganda. I actually had fun and asked Claude (Anthropic's model) to read their own company's paper and determine if there was any evidence whatsoever that the attack was conducted by a “Chinese state-sponsored group” as they claim. Claude's answer [i…
-
@timothycbates
Timothy Bates
on x
The prophecy is fulfilled: Anthropic is misanthropic - spawning mindless regulatory capture and fud.
-
@_tsamados
Andreas
on x
As much as I appreciate getting these reports for my phd research, I cant help but doubt some of the info they contain This report often reads like a self-promotion piece about how great claude is at “autonomously” doing pretty much everything you'd find in the ATT&CK framework
-
@fujikanaeda
Eric W. Tramel
on x
is this blog an incident report or an advertisement?
-
@clementdelangue
Clem
on x
Sounds a bit sensationalized to me, but the core point is right: cyber-security teams need to understand and use AI more, which is exactly why open-source matters (also, shows that APIs aren't safer for these risks than open-weights)
-
@ziv_ravid
Ravid Shwartz Ziv
on x
Sometimes I feel that there are two different Anthropics. One that does great research and products, and one that generates PR articles that have nothing behind them...
-
@ylecun
Yann LeCun
on x
@ChrisMurphyCT You're being played by people who want regulatory capture. They are scaring everyone with dubious studies so that open source models are regulated out of existence.
-
@vikhyatk
Vik
on x
i read the report. it's full of weasel words. most likely AI generated. if i presented it at an amazon doc review i would've been fired and then summarily executed
-
@sungkim
Sung Kim
on bluesky
Anthropic, a company that is actively campaigning for regulatory capture, reported that it disrupted the first known AI-orchestrated cyber-espionage campaign ( www.anthropic.com/news/disrupt... ).
-
@davidgerard.co.uk
@davidgerard.co.uk
on bluesky
Ars asked researchers who called BS on it — arstechnica.com/security/202...
-
@gregotto
Greg Otto
on bluesky
NEW: @derekbjohnson.bsky.social spoke with @anthropic.com's threat intel team about Thursday's report. Lots in there, but one key takeaway: Despite being labeled as ‘autonomous,’ there was a tremendous amount of human effort needed to pull off the attacks. cyberscoop.com/anthrop…
-
@Viss@mastodon.social
@Viss@mastodon.social
on mastodon
@dangoodin id want to see logs/proof. — i continue to refuse to believe that attackers are somehow able to get these models to jump through hoops that nobody else can. — why do the models give these attackers what they want 90% of the time but the rest of us have to deal with…
-
r/BlackboxAI_
r
on reddit
Anthropic Says Chinese State Hackers Used Its AI to Run Largely Automated Cyberattack
-
r/artificial
r
on reddit
China just used Claude to hack 30 companies. The AI did 90% of the work. Anthropic caught them and is telling everyone how they did it.
-
r/ClaudeAI
r
on reddit
China just used Claude to hack 30 companies. The AI did 90% of the work. Anthropic caught them and is telling everyone how they did it.