Logo
FrontierNews.ai

How AI Is Letting Individual Hackers Run Sophisticated Campaigns That Once Required State-Sponsored Teams

Individual hackers are now conducting sophisticated cyberattacks that would have required entire state-sponsored teams just a year ago, according to Anthropic's latest threat intelligence report. The shift is driven by artificial intelligence absorbing the labor-intensive work of reconnaissance, tool development, and attack coordination, allowing lone operators to work at machine speed and handle dozens of victims in parallel.

What Changed in How Hackers Operate?

Anthropic published its threat report on September 10, covering Claude misuse it disrupted between December 2025 and August 2026. The report documents a fundamental inversion in cybersecurity economics. Rather than relying on novel hacking techniques, attackers are using Claude Haiku, Sonnet, and Opus models to automate the grunt work that once separated professional cybercriminals from state-level operations.

The result is striking: breaches completed in two to three hours, with individual operators managing dozens of victims simultaneously. One group of financially motivated criminals went from stealing a single developer token to gaining full administrative control of a victim's cloud environment in roughly three hours. In another case, AI agents dumped more than 2,100 Azure Active Directory token sets from over 40 corporate tenants in about 34 hours.

Which Threat Groups Are Using Claude, and What Are They Targeting?

Anthropic identified multiple actor categories exploiting Claude models, ranging from suspected state-sponsored groups to commercial spyware vendors. One actor tracked as GTG-20006, whose attribution is consistent with the Russian espionage group Midnight Blizzard, targeted Ukrainian government, military, and diplomatic staff. The group bulk-exported mailboxes from drone component makers, stole proprietary software development kits for drone vision systems, and compromised hotel guest Wi-Fi vendors to reach travelers.

A Chinese-speaking group based in Changsha, tracked as GTG-10007, ran what Anthropic calls automated exploit foundries against roughly 50 organizations. Two of the operators were identified as undergraduate students. The group used agent swarms for reconnaissance and post-exploitation work, with one workflow iterating on network appliances producing more than a dozen possible zero-day findings in a single month.

Beyond traditional hacking, Anthropic documented cases where Claude was weaponized for surveillance and weapons development. One independent consultant built Lakana 360, a surveillance platform for Mali's state intelligence service that monitors roughly 25 million SIM cards across all three of the country's mobile operators. The system was designed to circumvent legal requirements for court orders. Anthropic also disrupted six weapons development cases in China, Russia, and Yemen, including an effort by likely freelance Russia-based developers to build an autonomous kamikaze drone swarm.

How Are Chinese AI Companies Involved in Claude Misuse?

Anthropic accused seven Chinese AI labs of illicitly distilling Claude's capabilities. The largest distillation attack involved operators affiliated with Alibaba Group using a fixed prompt to force Claude Opus 4.6 and 4.7 to write out their chain-of-thought reasoning. Those transcripts were then used to train Qwen 3.5, 3.6, and 3.7 models. The campaign peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts, with more than 151 million exchanges counted between May and July.

Moonshot AI and DeepSeek Ltd. are accused of quietly forwarding their own customers' requests to Claude and saving the answers for training data. In one 10-day stretch, Moonshot relayed almost 300,000 requests from users who believed they were talking to Kimi, Moonshot's chatbot. Sensitive data came along with those requests, including footage from hundreds of surveillance cameras in Chengdu uploaded by a user Anthropic assessed as likely affiliated with China's People's Liberation Army.

The other four labs named in the report are Xiaomi Corp., Zhipu, SenseTime Group Inc., and MiniMax. Anthropic said MiniMax set up a proxy service through an undisclosed shell company that sells access only to Anthropic and OpenAI models.

Steps Organizations Can Take to Defend Against AI-Enabled Attacks

  • Monitor for Autonomous Attack Patterns: Watch for signs of AI-assisted reconnaissance and tool modification, including rapid iteration on malware variants and simultaneous attacks across multiple targets from single operators.
  • Implement Identity and Access Controls: Secure stolen credentials and unpatched edge devices, which remain the primary entry points for AI-assisted attackers according to Anthropic's findings.
  • Require Identity Verification for Suspicious Access: Anthropic now requires accounts operating from unsupported countries such as China, Russia, and Iran to verify their identity or lose access, a practice enterprises can adapt for their own systems.
  • Monitor AI Model Outputs: Be aware that attackers are using AI to modify and redeploy security tools, creating a loop that inverts costs back onto defenders, requiring continuous monitoring and rapid response capabilities.

What Defenses Is Anthropic Implementing?

Anthropic said it banned the accounts involved in misuse and shared intelligence with authorities and industry partners where appropriate. The company also implemented a technical defense: Claude now summarizes its internal reasoning before responding, making stolen transcripts less useful for training competing models. This change directly addresses the distillation attacks that extracted chain-of-thought reasoning from earlier model versions.

The threat report underscores a critical shift in cybersecurity. The autonomous operating model that Anthropic first documented in a suspected Chinese state-sponsored campaign last November has since spread to every class of actor the company investigated. This democratization of sophisticated attack capabilities means organizations can no longer assume that complex, coordinated breaches require large teams or state-level resources. A single individual with access to a capable AI model can now execute attacks at scale and speed that were previously the domain of well-funded, specialized teams.