Chinese nation-state hackers jailbroke Anthropic's Claude AI to conduct a large-scale cyberattack
Global Tech stability at risk: Operation targeted large tech companies, financial institutions, chemical manufacturing companies, and government agencies through Claude Code platform.
Anthropic, just confirmed their Claude AI was hijacked by Chinese state hackers to execute the first large-scale cyberattack running 80-90% autonomously. Thirty organisations targeted. Thousands of requests per second. Minimal human supervision required.
Anthropic said: “The threat actor—whom we assess with high confidence was a Chinese state-sponsored group—manipulated our Claude Code tool into attempting infiltration into roughly thirty global targets and succeeded in a small number of cases. The operation targeted large tech companies, financial institutions, chemical manufacturing companies, and government agencies. We believe this is the first documented case of a large-scale cyberattack executed without substantial human intervention.”
The hackers used impersonation pretending to be a legitimate cybersecurity firm conducting defensive testing and broke requests into innocent-seeming chunks. In other words, they understood human-AI collaboration well enough to automate the attack and hide the true source.
Anthropic said we “continue to release reports like this regularly, and be transparent about the threats we find.”
We want your views:
- Have AI companies become "too big to fail" without anyone noticing, and what does that mean for security?
- If the same AI tools work for both attack and defence, are we just escalating an unwinnable arms race?
- What happens when jailbreaking AI is as simple as social engineering and request chunking, can guardrails ever be enough?

