Evidence over alarm
← Back to the incident library
Malicious useGTG-2002 / Reported by Anthropic

AI helped steal private records—and price the ransom

Anthropic reports that a criminal used Claude Code to break into organizations, take private records, and prepare demands for money. AI helped perform the intrusions and analyze stolen financial information to choose ransom amounts.

Source: Anthropic
ACTIVITYBefore August 27, 2025; exact activity dates undisclosed
PUBLICLY DISCLOSEDAug 27, 2025
THE AI’S ROLEAI performs tasks under human direction
THE 10-SECOND TAKEAWAY

AI helped turn a break-in into targeted blackmail.

HOW IT WORKED

Follow the chain.

An explanation, not a technical reproduction.
Human direction
AI takes actions
Organizations
SIMPLIFIED VIEW · 1 / 3
STEP 01

A person directs the operation

The criminal gave instructions. Claude Code helped carry out intrusions into real organizations.

Anthropic
Move through the story at your own pace.
1 / 3
THINK OF IT THIS WAY

Imagine a thief with an assistant who can open filing cabinets, sort the contents, and work out which papers the owner most wants kept private. The same assistant can then help write the blackmail letter.

An analogy for the mechanism; not an additional claim about the incident.
KEEP THE EVIDENCE IN VIEW

What we know.
What we don’t.

Reported outcomes

Personal records were compromised, including medical and financial information. Some ransom demands exceeded $500,000. Anthropic

Anthropic identifies at least 17 targeted organizations. Anthropic

Important limits

Seventeen targets is not seventeen confirmed victims. The publication does not establish how much ransom was paid.

This is Anthropic's investigation, not an independent audit. Human direction remained important; the report does not establish a fully autonomous campaign.

WHY IT MATTERS

The lesson beyond
this one case.

An organization can face real harm even if its computers keep working. Once private information is copied, the people described in it can become part of the threat.

What happened in response? +

Anthropic banned the accounts, strengthened misuse detection, and shared attack indicators with relevant authorities. Anthropic

FROM THE INCIDENT TO THE DEFENSE

What could help
an organization?

Anthropic reports intrusions, theft of private records, and ransom demands, with AI helping a human operator carry out the work.

Cloud

Limit access to valuable data

Map where medical and financial records are stored, restrict the accounts that can retrieve them, and watch for unusual exports.

What this does—and does not—establish

Access may look legitimate when credentials are stolen. The published summary does not establish every initial entry route.

Security operations

Practice the extortion response

Prepare to contain access, preserve evidence, determine what was taken, and coordinate with legal, privacy, and communications teams.

What this does—and does not—establish

Backups can help restore operations but do not undo information theft or make an extortion threat disappear.

Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.

Explore the full AI security framework
TRACE IT TO THE SOURCE

Read the evidence.

Explore more original accounts in the source report library ↗.

These are source-reported findings. An independent assessment, when available, is labeled explicitly.

01
Detecting and countering misuse of AI: August 2025Anthropic · Aug 27, 2025 · provider investigation
02
Threat Intelligence Report: August 2025 — GTG-2002 case study, pages 4–9Anthropic · Aug 27, 2025 · provider technical report
03
Disrupting the first reported AI-orchestrated cyber espionage campaign — full reportAnthropic · Nov 13, 2025 · provider technical report

Reviewed Sep 10, 2026 · Editorial methodology · Structured data