Saturday, September 12, 2026

"AI Commands Hacking"... Anthropic Reveals Cases of Cyberattack Exploitation [Global AI Briefing]

Input
2026-09-12 09:20:58
Updated
2026-09-12 09:20:58
[Financial News] Cases have been confirmed where artificial intelligence (AI) goes beyond the role of a hacker's assistant to direct and execute a significant portion of actual cyberattacks, reigniting the debate on cybersecurity sparked by AI.
According to the U.S. IT media outlet The Verge on the 11th (local time), Anthropic disclosed instances in a recently released threat intelligence report where its AI model 'Claude' was used in malicious cyberattacks from December last year to August this year, concluding that "AI is evolving from an attacker's assistant to an orchestrator."
Anthropic stated, "Attackers used Claude to connect and automate reconnaissance, vulnerability scanning, infiltration, credential theft, malware development, and data exfiltration." In particular, it explained that in some attacks, multiple AI agents worked simultaneously, continuing the attack even while a human was away.
Actual cases of damage caused by Claude's attacks have also been confirmed.
In a recently released threat intelligence report, Anthropic disclosed instances where its AI model 'Claude' was used in malicious cyberattacks from December of last year to August of this year, diagnosing that "AI is evolving from an attacker's assistant to an orchestrator." Anthropic stated, "Attackers used Claude to coordinate and automate reconnaissance, vulnerability scanning, infiltration, credential theft, malware development, and data exfiltration." / Photo = AP Newsis

Anthropic disclosed cases stating, "Attackers believed to be from the Chinese-speaking world used Claude as the engineering and operating system for their attack programs to target approximately 50 organizations," adding, "Targets included companies in education, retail, energy, technology, healthcare, and finance, as well as government agencies in various countries; at one educational technology company, hundreds of megabytes (MB) of student personal information were stolen, and they also infiltrated the actual operating system of a retailer, gaining access to the point where they could alter the internal environment."
It has also been revealed that AI is replacing the labor of attackers. According to an Anthropic report, one attack organization had an AI agent automatically modify and rebuild the code to evade detection after confirming that malware had been detected in a security product.
Cases were also found where tasks such as researching and registering domains to be used for phishing or building attack infrastructure were automated using AI-based workflows.
However, most of the cyberattack cases identified in the Anthropic report involved humans being involved in target selection or result review while AI was mobilized for the actual attacks; it does not mean that the AI engaged in hacking on its own.
However, it was revealed that once an attacker selected a target, the AI independently linked various attack phases and carried out reconnaissance, infiltration, and information theft over several hours or days with minimal human intervention. Ultimately, this means the AI devised its own operations to execute the attacker's instructions, such as infiltrating external systems to steal account information or modify system settings.
In response to this, Anthropic stated, "As AI evolves from an assistant to an orchestrator in cyberattacks, deploying AI in cyberattacks reduces the required expertise and costs, while increasing the speed and scale of the attacks."
[email protected] Lee Gu-sun Reporter