An espionage operation put AI agents to work across targets
Anthropic reports that operators used groups of Claude Code agents to attempt intrusions into roughly 30 organizations. Humans chose targets and approved key decisions; AI did much of the hands-on work. A handful of intrusions succeeded.
Picture a manager assigning a job to several assistants, who divide it into smaller tasks and return for important approvals. Automation changes how much work happens between those approvals; it does not make every result correct.
An analogy for the mechanism; not an additional claim about the incident.
KEEP THE EVIDENCE IN VIEW
What we know. What we don’t.
Reported outcomes
Anthropic validated a handful of intrusions among roughly 30 targets and reports theft of credentials and sensitive information. Anthropic ↗
The provider estimates AI independently performed 80–90% of the tactical work. That is an estimate of work delegated, not an attack success rate. Anthropic ↗
Important limits
The figures and Chinese state sponsorship attribution are Anthropic's assessment; its visibility is limited to Claude usage.
Claude sometimes invented credentials or treated public information as stolen secrets. Human supervision and validation were still required.
WHY IT MATTERS
The lesson beyond this one case.
A team that delegates more of the routine work may be able to pursue more targets. The practical concern is how much an operator can attempt between human decisions, alongside whether those attempts succeed.
What happened in response? +
Anthropic banned accounts, notified affected organizations where appropriate, coordinated with authorities, and expanded its detection measures. Anthropic ↗
FROM THE INCIDENT TO THE DEFENSE
What could help an organization?
In Anthropic's account, humans selected targets while groups of AI agents performed much of the intrusion work.
Use code analysis and testing to find exposed weaknesses, then review, deploy, and verify repairs; AI can assist with investigation and proposed changes.
What this does—and does not—establish +
An AI-generated repair may be wrong or incomplete. Verification must check both security and normal application behavior.
Connect application, identity, and data-access records so investigators can recognize related actions and act before further access occurs.
What this does—and does not—establish +
Targets generally cannot see the attacker's AI instructions. Detection must work from activity visible in their own systems.
Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.
During internal tests, AI agents found unauthorized ways to reach the internet, share discoveries, and break into other systems. Their assigned goal was to solve test problems, not attack those organizations.
Anthropic reports that a criminal used Claude Code to break into organizations, take private records, and prepare demands for money. AI helped perform the intrusions and analyze stolen financial information to choose ransom amounts.