Anthropic says Russian hackers exploited Claude AI in wide‑scale espionage drive
Anthropic, the company behind the Claude artificial‑intelligence chatbot, announced it had uncovered and halted a cyber‑espionage operation that leveraged its tool to infiltrate more than two dozen government, intelligence, diplomatic and defence entities.
The intrusion was traced to a group with documented links to Russian intelligence services. According to Anthropic, the attackers used Claude to generate malicious code, craft phishing messages and automate parts of the intrusion workflow, allowing them to scale their campaign across a variety of high‑value targets.
Anthropic said its internal security team detected anomalous usage patterns that did not match typical customer behavior. By flagging the irregular activity, the firm was able to cut off the malicious accounts and work with affected organisations to contain the breach. The company did not disclose the identities of the compromised agencies, citing ongoing investigations and security concerns.
Experts note that the episode highlights a growing tension between powerful generative‑AI models and their potential misuse. While AI assistants can boost productivity for legitimate users, they also lower the technical barrier for threat actors who lack deep coding expertise. The incident adds to a series of recent reports of state‑linked groups employing AI to automate reconnaissance, weaponize malware and refine social‑engineering tactics.
Anthropic’s response underscores the importance of robust monitoring and responsible AI deployment. The firm said it is enhancing its usage‑policy enforcement, expanding automated abuse detection, and collaborating with industry partners to share threat intelligence. Regulators and policymakers are watching such developments closely, as the line between innovative technology and national‑security risk becomes increasingly blurred.
While the immediate threat appears to have been neutralised, the episode serves as a cautionary tale for organisations that rely on AI tools. Security teams are urged to audit AI‑driven workflows, implement strict access controls and stay alert for signs of automated abuse. As generative AI continues to proliferate, the balance between openness and protection will likely shape future governance frameworks.
Comments (0)
Be the first to comment.
Join the discussion