AI News Feed
Market watch
Cybersecurity

Anthropic says AI lets lone operators run state-level hacking campaigns

Anthropic says AI lets lone hackers run state-level campaigns and accuses seven Chinese AI labs of distilling Claude.

The report spans seven harm areas. The actors it describes include suspected state-sponsored groups, financially motivated criminals and commercial spyware vendors. They used Claude Haiku, Sonnet and Opus models. Only one case, a distillation campaign, touched the company’s Fable or Mythos-class models.

None of the intrusions relied on a novel technique, according to Anthropic. Stolen credentials and unpatched edge devices feature throughout, while reconnaissance and tool development were handed to AI models running in parallel at machine speed. Anthropic said the result was “breaches completed in two to three hours, and dozens of victims handled in parallel by individual operators.” The autonomous operating model it first documented in a suspected Chinese state-sponsored campaign last November has since spread to every class of actor it investigated.

Anthropic said its attribution of one actor, GTG-20006, is consistent with public reporting on the Russian espionage group Midnight Blizzard. Ukrainian government, military and diplomatic staff were its most frequent targets. The operators bulk-exported the mailboxes of at least two drone component makers, stole a proprietary software development kit for a drone vision system and compromised hotel guest Wi-Fi vendors to reach travelers. Whenever security products flagged the group’s implants, Claude was used to modify and redeploy them, a loop Anthropic said has “inverted the cost back onto defenders.”

Affiliates of the ShinyHunters extortion collective went from a single stolen developer token to full administrative control of a victim’s cloud environment in roughly three hours during one compromise. In another, AI agents did nearly all the work of dumping more than 2,100 Azure Active Directory token sets from over 40 corporate tenants in about 34 hours.

A Chinese-speaking group tracked as GTG-10007, likely based in Changsha, ran what Anthropic calls automated exploit foundries against about 50 organizations. Two of the operators were identified as undergraduate students. The group used “agent swarms” for reconnaissance and post-exploitation work, and one workflow iterating on network appliances produced “more than a dozen possible zero-day findings” in a single month.

GTG-50020, a Russian-speaking financially motivated actor, turned to the AI industry after earlier intrusions against hotel booking and financial technology platforms. Its operators planted malicious instructions in an AI vendor’s automated evaluation sandbox, which handed over production application programming interface keys for several model providers. A follow-on campaign targeted roughly 30 AI companies in about four days. The stated goal was access to a pre-release Claude model, and Anthropic said every attempted path failed and its own systems were never breached.

On distillation, Anthropic said operators affiliated with Alibaba Group Holding Ltd. ran “the largest distillation attack we have ever measured.” A fixed prompt forced Claude Opus 4.6 and 4.7 to write out their chain-of-thought reasoning, and the transcripts were used to train Qwen 3.5, 3.6 and 3.7. The campaign peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts, with over 151 million counted between May and July.

Moonshot AI and DeepSeek Ltd. are accused of quietly forwarding their own customers’ requests to Claude and saving the answers for training. In one 10-day stretch, Moonshot relayed almost 300,000 requests from users who believed they were talking to Kimi. Sensitive data came along with them, including footage from hundreds of surveillance cameras in Chengdu uploaded by a user Anthropic assessed as likely affiliated with China’s People’s Liberation Army. A DeepSeek relay exposed live credentials for a Russian government database linked to the country’s Ministry of Defense.

The other four labs named are Xiaomi Corp., Zhipu, SenseTime Group Inc. and MiniMax. Anthropic said MiniMax set up a proxy service through an undisclosed shell company that sells access only to Anthropic and OpenAI Group PBC models. Anthropic first accused Chinese labs of distillation in February.

The report also described Lakana 360, a surveillance platform built with Claude for Mali’s state intelligence service by what Anthropic believes was a single independent consultant. It monitors roughly 25 million SIM cards on all three of the country’s mobile operators.