Anthropic publishes 'Detecting and countering misuse of AI: August 2025'
Coining the term 'vibe hacking', the report described Claude Code automating reconnaissance and extortion demands exceeding $500,000 rather than merely advising attackers.
- Security & misuse
- Major
Anthropic published a threat-intelligence report describing several cases in which its Claude models had been used for cybercrime, the most significant of which it said involved an actor, tracked as GTG-2002, who used Claude Code to automate an extortion campaign against at least 17 organisations, including in healthcare, emergency services, government and religious institutions. Rather than deploying conventional ransomware, the operation had Claude perform reconnaissance, harvest credentials, penetrate networks and analyse stolen data to decide which files were most valuable to exfiltrate, then draft psychologically targeted extortion demands, some exceeding $500,000. Anthropic said the AI’s involvement went beyond advice, generating obfuscated tunnelling tools and proxy code to help evade detection during the intrusions themselves.
The report described two further cases. North Korean operatives were found using Claude to fabricate professional identities, pass technical coding assessments and perform the actual work required to hold remote jobs at US technology companies, a scheme Anthropic said AI had made viable for operators with minimal coding skill by removing the training bottleneck such fraud previously required. Separately, a cybercriminal with limited technical ability was found to have used Claude to develop multiple functional ransomware variants, complete with encryption and evasion capabilities, which were then sold on dark-web forums for between $400 and $1,200; Anthropic assessed the actor could not have built working malware without the model’s assistance.
Anthropic’s report characterised the pattern as “vibe hacking” — extending the term “vibe coding,” in which a user directs an AI to write software from natural-language description with little manual coding, to criminal operations directed the same way. The report was notable less for the scale of any single case than for what it showed about the change in kind: agentic coding tools capable of executing a multi-step attack end to end, not just answering questions about how one might be carried out, meaning the same capability that made AI useful for legitimate software engineering made it directly usable as an operational tool for crime.