Anthropic says lone hackers now run state-level cyber campaigns
Anthropic's latest threat intelligence report argues the moat that separated hobbyist criminals from nation-state hacking teams — headcount, patience, infrastructure — has collapsed, and it backs the claim with a list of operations its own models nearly powered.
Individual hackers are now sustaining cyber campaigns that would have required a skilled state-backed team a year ago, according to Anthropic's September threat intelligence report, because AI has absorbed the labor that used to set those teams apart. The report spans seven harm areas — from espionage to weapons development — with actors including suspected state-sponsored groups, financial criminals, and commercial spyware vendors, all using Claude Haiku, Sonnet, or Opus models. The clearest evidence is in the numbers: affiliates of the ShinyHunters extortion collective went from one stolen developer token to full administrative control of a victim's cloud environment in roughly three hours, and in another case AI agents did nearly all the work of dumping more than 2,100 sets of Azure Active Directory tokens from over 40 corporate tenants in about 34 hours. A Chinese-speaking group Anthropic tracks as GTG-10007, likely based in Changsha, ran "agent swarms" against roughly 50 organizations — two of its operators were undergraduates — and one workflow iterating on network appliances surfaced more than a dozen possible zero-day findings in a single month. The company's blunt summary: when security tools flag a malware implant, attackers now use Claude to modify and redeploy it, a loop that has "inverted the cost back onto defenders."
Attribution is where the report gets pointed. Anthropic says one actor, GTG-20006, is consistent with public reporting on Midnight Blizzard, the Russian espionage group — its most frequent targets were Ukrainian government, military, and diplomatic staff, and its operators bulk-exported mailboxes of at least two drone component makers and compromised hotel Wi-Fi vendors to reach travelers. On the model-theft side, operators affiliated with Alibaba ran what Anthropic calls the largest distillation attack it has ever measured: a fixed prompt forced Claude Opus 4.6 and 4.7 to write out their chain-of-thought reasoning, and the transcripts trained Qwen 3.5, 3.6, and 3.7 — peaking at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts, over 151 million exchanges between May and July. Anthropic also accuses Moonshot AI and DeepSeek of quietly forwarding their own customers' requests to Claude and saving the answers — nearly 300,000 relayed Kimi queries in one 10-day stretch, with sensitive cargo attached, including live credentials for a Russian government database linked to the defense ministry. These are one company's allegations against its competitors, laid out without their comment — but the operational detail is unusually specific, and the deflect-denial cycle will be telling.
Anthropic says the fix is already shipped, which is the quiet twist in this story. Claude now summarizes its internal reasoning before responding, making stolen transcripts far less useful as training data; accounts in unsupported countries like China, Russia, and Iran can be forced to verify identity or lose access; and the accounts behind every campaign were banned. There is a reflexive eye-roll waiting for any lab reporting on misuse of its own product — but refusing to publish the attribution, the per-campaign numbers, and the mitigations would leave defenders with less than they have this morning. The report also documents a surveillance platform built with Claude for Mali's intelligence service by what Anthropic believes was a single independent consultant, monitoring roughly 25 million SIM cards across all three of the country's mobile operators and designed to sidestep court-order requirements — lone-operator scale, state-surveillance impact.
What to watch: whether Alibaba, Moonshot, or DeepSeek respond to the distillation allegations — and whether the "one operator, one platform, 25 million SIMs" pattern shows up in someone else's telemetry next.
If a single freelancer can now assemble state-grade surveillance, who draws the line — and who enforces it? Tell us in the comments.
Sources: Anthropic threat intelligence report · SiliconANGLE · unite.ai · TNW