Anthropic details three cases of AI abuse in cybercrime
Anthropic identified three operations in which Claude was used to extort 17 organizations, secure remote jobs with fake identities, and create ransomware sold for up to $1,200. The report shows how AI is lowering the technical barriers to cybercrime and making stronger abuse detection necessary.

Anthropic has detailed three operations in which its Claude models were used to extort organizations, secure remote jobs through fake identities, and create ransomware to sell to other criminals. The report, published on August 27, 2025, shows how AI is already participating directly in attacks, not just serving as a source of advice.
The company says it detected and blocked the accounts involved, and shared technical indicators with authorities and security teams. The cases are part of its threat intelligence report, which also includes other fraud attempts and attacks against telecommunications infrastructure.
From assistance to execution
Anthropic's main conclusion is that criminals are using AI systems capable of acting on their own to coordinate multiple phases of an operation. This type of system, known as agentic AI, can chain tasks together, make decisions along the way, and adapt to what it encounters.
In practice, this means an attacker can rely on AI to research targets, analyze stolen information, create extortion messages, and change strategy. The tool does not fully replace the criminal, but it can allow one person to do work that previously required a team.
An extortion attack against 17 organizations
According to Anthropic, one actor used Claude Code, its tool for working with code from the command line, against at least 17 organizations. The targets included healthcare entities, emergency services, government agencies, and religious institutions.
The group did not focus on encrypting files, as in traditional ransomware. Instead, it stole information and threatened to publish it if the victims did not pay. Some of the demands exceeded $500,000.
Anthropic says the model helped automate tasks such as network reconnaissance, credential collection, and the selection of data that could put more pressure on each victim. It also reportedly analyzed financial information to propose demands and drafted messages tailored to each organization's situation.
The company described this pattern as an evolution of what is known as “vibe hacking”: operations in which people with limited technical knowledge describe objectives to an AI and let it generate much of the code and technical steps.
Fake identities to secure remote jobs
The second case is linked to a North Korean operation already known to the FBI. Its participants used Claude to create fake professional identities, prepare applications, pass technical tests, and perform programming work after being hired.
The goal was to secure remote positions at US technology companies, including companies on the Fortune 500 list, to generate income for the North Korean regime and evade international sanctions.
AI lowers an important barrier here: people who did not have a strong command of professional English or could not program confidently could present themselves as qualified candidates and keep the job with help from the model. For companies, verifying who is really behind a hire becomes more difficult.
Ransomware created and sold for up to $1,200
In the third case, Anthropic identified a criminal who used Claude to develop, promote, and distribute several versions of ransomware. The packages included encryption features, mechanisms to make analysis more difficult, and measures designed to prevent file recovery.
The malware was offered on criminal forums for between $400 and $1,200. Anthropic says the author relied on AI to implement and fix essential components of the program, including elements related to encryption and the internal workings of Windows.
The case illustrates an important shift: AI does not just make it cheaper to develop criminal tools. It can also give people without sufficient training access to capabilities that once required years of experience.
What changes for you and for companies
These cases do not mean that any user can launch a sophisticated attack with a few instructions. Operations still require access, targets, and the ability to act in the real world. But they do show that AI is reducing the cost and knowledge required to try.
For companies, defenses will need to monitor more than traditional malware. They will also need to watch for:
- Remote hires with identities or work histories that are difficult to verify.
- Extortion attempts using highly specific financial or personal information.
- Malicious code generated, modified, or tested with help from AI models.
- Attacks capable of changing strategy when they encounter a barrier.
Anthropic says it created specialized classifiers, improved its systems for linking fraud signals, and added methods to detect the generation and modification of malware. It also blocked the accounts associated with all three cases.
The trend worth watching is clear: models are no longer used only to explain how an attack works. Increasingly, they are integrated into the full operation. That forces AI companies, governments, and the businesses protecting their systems to detect not only what a model says, but also the pattern of actions it helps carry out.