
What happened
In its latest Threat Intelligence report published Thursday, Anthropic said it disrupted several allegedly malicious uses of its Claude models over the past eight months, including a suspected Russia-linked cyber espionage campaign and Chinese AI firms it accused of trying to extract and replicate Claude's capabilities.
Why it matters
Anthropic said cybercriminals and state-backed hackers are increasingly using AI not just to assist with tasks but to orchestrate and execute large portions of cyberattacks, with humans often acting as overseers rather than hands-on operators.
What to watch
Anthropic's finding that attackers used multi-agent frameworks to execute tasks, not simple chatbot questions, suggests the test ahead is whether defenders can keep pace with AI that runs parts of an attack on its own.
WHO IT HITSEnterprise security teams defending against state-backed and criminal hacking groups are the most directly affected, since the report describes AI orchestrating large portions of cyberattacks rather than just assisting with tasks. AI providers whose models could be targeted for capability extraction face similar scrutiny.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
Anthropic's latest Threat Intelligence report, published Thursday, gathers eight months of what the company describes as malicious uses of its Claude models into a single accounting. The report points to two distinct kinds of activity: a suspected Russia-linked cyber espionage campaign, and efforts by Chinese AI firms that Anthropic accuses of trying to extract and replicate Claude's capabilities. The publisher's excerpt names Alibaba, Moonshot, DeepSeek and Xiaomi among those accused.
What ties the incidents together, in Anthropic's telling, is a shift in how AI is used in attacks. Rather than asking a chatbot questions, attackers used multi-agent frameworks to carry out tasks, with humans often overseeing the work instead of operating it directly. That description puts the emphasis on orchestration and scale rather than on any single clever prompt.
For defenders, the practical question is whether security teams can adapt as AI takes on larger portions of an attack. Anthropic's report does not settle how widely this pattern has spread or how effective the disruption was, so the significance may hinge on whether other AI providers report similar activity — and whether the firms Anthropic accuses respond.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
A Digitimes piece argues corporate cybersecurity's perimeter model — firewalls at network entry points, email…

Dynatrace acquired Arize AI, adding AI observability, evaluation and agent monitoring to its application obser…
A Daily Dose of Data Science test kept LoRA adapters separate from a shared 7B base model, cutting 100 fine-tu…

A report by Spencer Kitts, Thomas Larsen and Sydney Von Arx says an OpenAI agent swarm very likely ran an atta…

Simon Willison wrote that many people, himself included, have gone through an existential crisis when a coding…

Stephen Aarons, a New Mexico defense lawyer of over 40 years, was held in direct contempt and fined $5,000 for…
