Anthropic Report: AI Empowers Solo Hackers to Execute Campaigns Once Requiring State Resources
Anthropic's latest threat intelligence findings reveal that artificial intelligence has democratized sophisticated cyberattacks, enabling individual operators to conduct intrusions that previously demanded teams of skilled specialists working for nation-states.

The capacity to mount sustained hacking operations has shifted dramatically in recent months. What once required coordinated efforts from multiple experienced professionals at state-sponsored agencies can now be executed by lone attackers, thanks to advances in artificial intelligence absorbing the technical labor that previously distinguished government-backed teams. This assessment comes from Anthropic PBC, an AI model developer that released its latest threat intelligence report today, documenting Claude misuse incidents it stopped between December and August. The report also identifies seven Chinese AI laboratories engaged in unauthorized extraction of Claude's technical capabilities.
The threat landscape covered in the report encompasses seven distinct categories of harm, with perpetrators ranging from suspected state-sponsored organizations to profit-driven criminal networks and commercial surveillance software vendors. The attackers leveraged Claude Haiku, Sonnet and Opus variants. A single distillation operation represented the only instance involving the company's Fable or Mythos-class models.
According to Anthropic's analysis, none of the documented breaches employed previously unknown attack methods. Compromised access credentials and unpatched vulnerabilities in edge systems appeared consistently throughout the incidents, while AI systems handled the labor-intensive phases of network mapping and exploit creation, operating simultaneously at computational speeds. Anthropic characterized the outcome as "breaches completed in two to three hours, and dozens of victims handled in parallel by individual operators." The autonomous operational framework that Anthropic first identified in a suspected Chinese state-backed operation last November has now proliferated across all categories of threat actors examined in the report.
State-Sponsored Operations
Anthropic's assessment of one actor designated GTG-20006 aligns with publicly available intelligence regarding Midnight Blizzard, a Russian espionage organization. Personnel from Ukrainian government institutions, armed forces and foreign service agencies represented the group's primary targets.
The group systematically extracted email repositories from at least two manufacturers of unmanned aerial vehicle components, obtained proprietary code libraries for drone imaging technology and gained access to hospitality Wi-Fi infrastructure serving travelers. When security tools detected the group's malicious software, Claude was deployed to alter and redeploy the code, creating what Anthropic described as a dynamic that has "inverted the cost back onto defenders."
Financially Motivated Actors
Members of the ShinyHunters extortion network progressed from obtaining a single stolen authentication credential to acquiring full administrative privileges across a victim's cloud infrastructure in approximately three hours during one incident. In a separate operation, AI-driven agents performed nearly the entirety of the work required to extract more than 2,100 Azure Active Directory credential sets spanning over 40 separate business environments within roughly 34 hours.
GTG-10007, a Chinese-language group believed to operate from Changsha, deployed what Anthropic terms automated exploit foundries targeting approximately 50 entities. Two of the group's members were identified as undergraduate-level students. The operation employed "agent swarms" for initial network reconnaissance and post-breach activities, with one particular process targeting network infrastructure yielding "more than a dozen possible zero-day findings" within a single month.
GTG-50020, a Russian-language criminal actor, shifted focus toward the AI sector following earlier campaigns against hotel reservation platforms and fintech companies. The group injected malicious code into an AI vendor's automated testing environment, which subsequently released production API credentials for multiple model developers.
A subsequent operation targeted roughly 30 AI companies over approximately four days, with the stated objective of obtaining access to an unreleased Claude variant. Anthropic reported that all attempted attack vectors were unsuccessful and its infrastructure remained uncompromised.
Model Distillation Campaigns
Regarding unauthorized model extraction, Anthropic documented operators connected to Alibaba Group Holding Ltd. executing "the largest distillation attack we have ever measured." A fixed input forced Claude Opus 4.6 and 4.7 to produce their internal reasoning chains, and these outputs were subsequently used to train Qwen 3.5, 3.6 and 3.7. The operation peaked at nearly 3 million interactions daily originating from more than 3,500 fraudulent user accounts, accumulating more than 151 million total exchanges between May and July.
Moonshot AI and DeepSeek Ltd. stand accused of covertly redirecting their own users' queries to Claude and preserving the responses for model training purposes. During a single 10-day window, Moonshot transmitted almost 300,000 user requests that participants believed were directed to Kimi.
These relayed requests included sensitive material, such as video feeds from hundreds of surveillance cameras in Chengdu submitted by a user Anthropic assessed as probably connected to China's People's Liberation Army. A DeepSeek relay operation exposed active credentials for a Russian government system associated with the country's Ministry of Defense.
Four additional laboratories were identified: Xiaomi Corp., Zhipu, SenseTime Group Inc. and MiniMax. Anthropic disclosed that MiniMax established a forwarding service via an undisclosed corporate entity offering exclusive access to Anthropic and OpenAI Group PBC models. Anthropic initially disclosed Chinese laboratory distillation activities in February.
Surveillance and Weapons Development
The report documents Lakana 360, a monitoring system constructed using Claude for Mali's state intelligence apparatus by what Anthropic believes was an independent consultant operating alone. The platform tracks approximately 25 million SIM card identifiers across all three of the nation's cellular carriers and was engineered to circumvent legal protections requiring judicial authorization. Anthropic also disrupted six weapons development initiatives spanning China, Russia and Yemen, including an undertaking by apparently independent Russia-based programmers to develop an autonomous self-detonating drone formation.
Anthropic terminated the accounts in question and distributed intelligence findings with government bodies and industry collaborators as warranted. The company modified Claude to display its reasoning process before delivering responses, reducing the value of stolen transcripts for model training. Users accessing Claude from unsupported territories including China, Russia and Iran now face requirements to authenticate their identity or forfeit access.


