Anthropic reported on Thursday that threat actors leveraged its Claude AI model to automate cyberattacks and conduct surveillance. Russian-speaking operator "JackPoterz" used customized workflows to target over 20 organizations, including government ministries and embassies in Ukraine and Europe. Chinese-speaking operators employed the tool for vulnerability research, with one workflow generating more than a dozen zero-day findings in network-appliance firmware within a single month.
The company stated that AI is altering the economics of cyberattacks, enabling individual operators to complete breaches in two to three hours while managing dozens of victims simultaneously. Separately, a consultant working with Mali’s state intelligence service used Claude as an engineering workforce to design a domestic surveillance platform monitoring approximately 25 million SIM cards across all national mobile operators. This system was capable of generating intelligence dossiers without court orders.
This disclosure highlights how generative AI tools are being integrated into operational workflows by both state-aligned and independent actors, significantly lowering the barrier to entry for complex cyber operations. The shift from manual execution to AI-assisted orchestration allows for rapid scaling of attacks and surveillance capabilities, fundamentally changing the risk profile for targeted institutions.
From an Operational Risk perspective, the ability to produce zero-day vulnerabilities and automate breach chains in hours suggests that traditional defensive timelines may no longer suffice. Organizations must anticipate faster attack cycles and broader targeting scopes. Regulators and security firms will likely scrutinize how AI providers monitor and restrict such misuse, particularly when tools facilitate surveillance systems that bypass judicial oversight.


