Anthropic's August 2025 threat intelligence report describes a criminal who used Claude Code to automate reconnaissance, credential harvesting and network intrusion against at least 17 organizations, including healthcare, emergency services, government and religious institutions, then threatened to publish the stolen data. The report also describes North Korean operatives using Claude to obtain and keep remote technical jobs, and a low-skill actor selling ransomware developed with Claude.
Why it matters
Anthropic presents it as agentic AI carrying out attacks rather than only advising on them, with a human still directing the operation.
Key facts
As stated in the sources, with where to find them.
- Ransom demands sometimes exceeded $500,000, Anthropic reports.Vibe hacking case study
- Anthropic says Claude was allowed to make tactical and strategic decisions, including which data to exfiltrate and how to frame extortion demands.Vibe hacking case study
- Ransomware variants developed with Claude were sold on forums for $400 to $1,200; Anthropic says the seller could not build or troubleshoot core components without AI.No-code malware case study
- Anthropic banned the accounts involved and shared indicators with partners and authorities.Our response
Findings that cite this record
Key questions this bears on
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
Nov 13, 2025
May 11, 2026
Jun 3, 2026
Jan 24, 2024
Nov 5, 2025
Sep 25, 2026