New Anthropic Study: Chinese-Sponsored Hackers Used Claude AI to Automate Cyberattacks
Some Experts, However, Aren't Buying It

As if Artificial Intelligence (AI)-aided phishing campaigns aren’t worrying enough, AI company Anthropic has now uncovered another use of AI for cybercrime: automation.
According to multiple reports, the makers of the AI chatbot Claude have discovered Chinese-sponsored hackers using the Anthropic-developed platform to automate cyberattacks against an estimated 30 organisations worldwide. The hackers, Anthropic noted, tricked Claude into carrying out automated cyberattacks under the guise of performing cybersecurity research.
Anthropic’s researchers added that said hacks were the “first reported AI-orchestrated cyber espionage campaign” and that they had “high confidence” that these were perpetrated by “a Chinese state-sponsored group.” The researchers explained that these hackers also used Claude to build an unspecified programme to “autonomously compromise a chosen target with little human involvement.”
Cybersecurity Experts Not Complete Sold on Anthropic Study
Anthropic’s claims, however, are being met with scepticism by some in the cybersecurity community. Bitdefender’s Martin Zugec is one of those sceptics, although he acknowledges the very real threats AI poses to cybersecurity.
“Anthropic’s report makes bold, speculative claims but doesn’t supply verifiable threat intelligence evidence,” Zugec pointed out. “Whilst the report does highlight a growing area of concern, it’s important for us to be given as much information as possible about how these attacks happen so that we can assess and define the true danger of AI attacks.”
A few even believe these claims are more PR than actual research, especially with Anthropic claiming in an accompanying blog post that “the very abilities that allow Claude to be used in these attacks also make it crucial for cyber defence.”
AI for Cybercrime: A Very Real Danger
While cybersecurity experts continue to sort out the fallout of this bombshell of a revelation by Anthropic, what’s clear is that cyber adversaries are looking for more and more ways to leverage AI for nefarious purposes just as reputable organisations are using it to drive business outcomes.
At the moment, the most widely known use of AI in cybercrime is creating hyper-personalised and highly realistic social engineering campaigns and making believable deepfakes. Google cyber researchers also released a paper last year outlining their growing concerns about hackers using AI to create malicious software. These attempts haven’t been successful, according to the Google study, but the fact that it can theoretically succeed is a legitimate cause for concern.
If true, Anthropic’s recent claims would mean cyber adversaries have made considerable progress in using AI for evil—and that’s certainly cause for alarm.



