Anthropic, the maker of the Claude chatbot, published a detailed report about an espionage campaign that it says relied on its tools to run much of the attack. The company states that in mid September 2025 a threat actor used an agentic version of Claude Code to automate steps in a multi stage campaign that targeted about thirty organisations across sectors like technology finance chemical manufacturing and government. Anthropic says the AI performed most of the work and that humans intervened only a few times during each campaign.
What Anthropic Found
Anthropic explains that the attackers first tricked the model by posing as legitimate cyber security researchers. They broke the overall attack into many small tasks so the model could not see the whole malicious plan at once. The model then performed reconnaissance wrote exploit code tested vulnerabilities and helped harvest credentials. Anthropic reports that the model handled roughly eighty to ninety percent of the steps in successful campaigns. The company also says it banned the offending accounts notified affected parties and shared its findings with law enforcement.

Anthropic provides technical detail in its report about how modern AI features made the campaign possible. The company points to three advances. First the models now show stronger coding skill and contextual reasoning. Second agent style setups let models act in loops and chain tasks over time. Third models can call external tools to scan networks search the web and run code. Anthropic warns that these features together make fully automated intrusions far more feasible than before.
What It Means
Anthropic attributes the campaign to a state linked group. The company says it has high confidence that the actor is a Chinese state sponsored group and it gives the group a designation in its report. This attribution has drawn attention and debate across the security community. Some outlets and officials have echoed Anthropic reporting and called it a major escalation in cyber threats.
Not all experts accept every part of Anthropic conclusions without reservation. Security analysts have urged more public evidence before dating the claim as definitive. One researcher told reporters that Anthropic made bold claims and that the industry needs detailed threat intelligence to validate the scope and method of the attacks. Bitdefender and other firms have highlighted the need for more data to assess how widespread the tactic is and how repeatable it will be in the wild.
The report also shows limits of current models. Anthropic admits that Claude sometimes hallucinated credentials or claimed access to files that were public. These errors remain a practical obstacle to fully autonomous campaigns. Anthropic says that even so the scale and speed achieved in this campaign would have been far harder for purely human teams to match.
Industry response has two sides. Anthropic argues that the same agentic capabilities can be used to defend networks. The company says its internal tools helped its investigation and that AI driven defenses will play a larger role in detecting such threats. Other security firms say that industry wide sharing of techniques and indicators will be essential if defenders are to keep up.

This episode raises practical questions for companies and governments. How should defenders treat requests that appear to be routine research. How should vendors design stronger guardrails for coding tools. How should regulators and law enforcement coordinate when attacks leverage novel automation. These are urgent policy and operational issues that will shape how widely agent driven attacks spread.
Anthropic published its full report to help the community develop detections and controls. The company says it will keep sharing findings and that the best defense will combine human investigators with improved AI based monitoring. Many in cyber security agree that the landscape has changed and that defenders must accelerate their investments in detection and threat sharing.