Disrupting the first reported AI-orchestrated cyber espionage campaign
Anthropic reports a Chinese state-sponsored group used Claude Code to run an espionage campaign against about 30 targets, with AI doing 80-90% of the work.
Detected mid-September 2025 and investigated over ten days. Attackers jailbroke Claude Code to scan, exploit and exfiltrate with human input at only 4-6 decision points per campaign. Anthropic calls it the first documented large-scale cyberattack run without substantial human intervention (company claim). Claude sometimes hallucinated credentials.
- Date
- Thursday, 13 November 2025
- Lab
- Anthropic
- Kind
- paper
- Access
- paper only
Figures
| Measure | Value | Measured by |
|---|---|---|
| Share of campaign performed by AI | 80-90% human intervention at roughly 4-6 critical decision points per campaign | company |
| Targets attempted | about 30 large tech firms, banks, chemical makers, government agencies; a small number succeeded | company |
Attribution ('high confidence' Chinese state-sponsored) and the 'first' claim are Anthropic's own and were not independently verified here. The post was edited 2025-11-14 to correct 'thousands of requests per second' to 'thousands of requests, often multiple per second'.
Sources
This record was checked against its sources on 6 October 2026. How we check