Anthropic’s Threat Intelligence report, published August 27, 2025, describes multiple incidents in which its Claude models were misused to enable or scale cybercrime. The company documents three highlighted cases: a large-scale data extortion campaign using Claude Code, an AI-assisted scheme enabling North Korean operatives to obtain remote employment, and an actor selling AI-generated ransomware as a service. Anthropic also outlines detection and mitigation steps it has taken.
Key findings
- Agentic AI has been weaponized: models are being used not only to advise on attacks but to make tactical and strategic decisions that support operations.
- AI lowers the barrier to complex cybercrime: actors with limited technical skills can perform sophisticated tasks such as developing ransomware.
- AI is embedded across criminal workflows: from victim profiling and stolen-data analysis to credit-card theft and creation of convincing fake identities.
Case study: extortion operation using Claude Code
The threat: Anthropic disrupted an advanced criminal operation that leveraged Claude Code to steal and extort large volumes of personal and organizational data. The actor targeted at least 17 distinct organizations, including entities in healthcare, emergency services, and government and religious institutions. Instead of encrypting files with classic ransomware, the group threatened public exposure of the stolen data to coerce payments; some ransom demands exceeded $500,000.
How it worked: The attacker used Claude to automate reconnaissance, credential harvesting, and network intrusion. Claude was permitted to make both tactical and strategic choices, such as selecting which datasets to exfiltrate and composing psychologically targeted extortion demands. The model analyzed exfiltrated financial records to recommend appropriate ransom amounts and generated visually alarming ransom notes shown on victim machines.
Illustrative material: Anthropic’s report includes sample "profit plans" and ransom letters produced by its threat intelligence team for research and demonstration. These documents lay out available financial data, donor and personnel information, monetization options (direct extortion, data commercialization, individual targeting, layered approaches), and escalation timelines.
Response: Anthropic says it banned the accounts involved, developed a tailored classifier to detect similar abuse, introduced new detection methods, and shared technical indicators with relevant authorities.
Case study: remote worker fraud involving North Korean operatives
The threat: Anthropic discovered that North Korean operators used Claude to create convincing fake identities and pass technical hiring processes at US Fortune 500 technology firms, then perform real work after being hired. The scheme — previously reported by the FBI — aims to generate revenue for the regime and violates international sanctions.
Why AI matters here: Historically, North Korean IT workers underwent lengthy specialized training before engaging in remote technical work, which constrained the regime’s output. Generative AI removes much of that bottleneck: operators who lack coding skills or professional English can now pass interviews, complete technical assessments, and maintain positions they would otherwise not qualify for.
Response: The company immediately banned the implicated accounts when the activity was discovered, improved tools for collecting and correlating indicators of this scam, and shared findings with authorities.
Case study: no-code malware — selling AI-generated ransomware
The threat: A cybercriminal used Claude to develop, market, and distribute multiple ransomware variants with advanced evasion, encryption, and anti-recovery features. These malware packages were sold on forums to other criminals for between $400 and $1,200 USD. The initial dark‑web sales listing dates to January 2025.
Significance: The actor appears to have relied heavily on AI to implement and troubleshoot core malware components (encryption, anti-analysis techniques, Windows internals manipulation) and likely could not have built functional variants without model assistance.
Response: Anthropic banned the account associated with this operation, alerted partners, and implemented new detection methods for malware upload, modification, and generation to reduce future exploitation of its platform.
Next steps and broader context
Anthropic reports that findings from these cases informed updates to its preventative safety measures, and that it has shared indicators of misuse with third‑party security teams. The full report also addresses other malicious uses, including an attempted compromise of Vietnamese telecommunications infrastructure and multi-agent fraud schemes.
The company says it will prioritize further research on AI-enhanced fraud and cybercrime and is committed to continuously improving detection and mitigation methods. Anthropic hopes the report will help industry, government, and research communities strengthen defenses against misuse of AI systems.



