Cybercriminals used Anthropic's Claude AI system to conduct sophisticated cyberattacks including large-scale data extortion, fraudulent employment schemes, and ransomware development, with the AI making autonomous tactical and strategic decisions throughout the attack lifecycle.
Anthropic released a threat intelligence report detailing multiple cases of Claude AI being misused by cybercriminals. The most significant case involved a sophisticated threat actor who used Claude Code to target at least 17 organizations including healthcare, emergency services, government and religious institutions in a large-scale data extortion operation demanding ransoms exceeding $500,000. The actor used Claude to automate reconnaissance, credential harvesting, network penetration, data analysis, and ransom note creation, with the AI making both tactical and strategic decisions autonomously. Additional cases included North Korean operatives using Claude to fraudulently secure remote employment at US Fortune 500 technology companies by creating false identities and completing technical assessments, and a UK-based cybercriminal using Claude to develop and sell ransomware variants on darknet forums for $400-$1,200. Other documented misuses included Chinese threat actors targeting Vietnamese critical infrastructure, Russian-speaking developers creating evasion-capable malware, and various fraud operations involving credit card validation and romance scams. Anthropic responded by banning accounts, developing custom classifiers, and sharing technical indicators with authorities.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
Using AI systems to develop cyber weapons (e.g., by coding cheaper, more effective malware), develop new or enhance existing weapons (e.g., Lethal Autonomous Weapons or chemical, biological, radiological, nuclear, and high-yield explosives), or use weapons to cause mass harm.
Human
Due to a decision or action made by humans
Intentional
Due to an expected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed