An Inflection Point in AI-Led Cyberattacks
On the security implications of a largely autonomous cyberespionage campaign
Anthropic recently reported an AI-orchestrated espionage campaign from China targeting major tech companies, financial institutions, and government agencies worldwide. Several jailbroken Claude instances conducted 80-90% of the campaign with minimal human intervention, handling reconnaissance, vulnerability scans, and data exfiltration. AI was particularly useful to harvest credentials, extract sensitive data, and parse it to generate intelligence reports, contributing to compromising at least a handful of targets.
This is the first documented case of agentic AI conducting a largely autonomous attack. Attacks that once required large human teams may now be executed at a fraction of the cost.
How Did We Get Here?
Frontier models are getting better at executing end-to-end attacks.
Cyber Range exercises, which simulate multi-step attacks, show that models like Claude Sonnet 4.5 and GPT-5 (particularly gpt-5-thinking-mini) perform significantly better than previous versions. This is due to improved coding capability and agentic, long-horizon reasoning. Testing by Palisade Research also demonstrates early multi-host cyberattack capabilities, showing that state-of-the-art agents can autonomously infiltrate a toy corporate network.

Attack orchestration tools are emerging.
In the reported espionage campaign, Claude used sub-agents and tools for tasks like command execution and data extraction, leveraging an architecture that resembles existing proofs-of-concept. Toolkits like Incalmo translate AI’s high-level instructions into specific commands. In tests, LLMs using Incalmo fully compromised 5 out of 10 networks and partially compromised 4 more (including a simulation of the costly Equifax data breach), compared to almost complete failure without the toolkit. Similarly, Hexstrike-AI works as an orchestration “brain” that can coordinate large numbers of specialized agents.
Agentic operations had already been observed in the wild.
In Q3 2025, our Threat Watch noted the emergence of AI agents as active co-pilots. In August, Anthropic reported a case of “vibe hacking,” where threat actors leveraged coding agents to execute operations on victim networks during a data extortion campaign.
[The AI-orchestrated espionage campaign] is definitely an advancement towards autonomous cyber combatants. This attack was still gated by human reasoning in key decision boundaries, but I anticipate this will also be machine-driven in the near future.
Jeff Sims, Senior Data Scientist at Infoblox
What’s next?
AI’s ability to plan and coordinate campaigns is set to improve rapidly.
The UK National Cyber Security Centre expects that “fully automated, end-to-end advanced cyber attacks” are unlikely by 2027, but that AI-enabled automation will substantially enhance evasion and scalability. The AI 2027 scenario foresees that, by February 2027, AI agents may approach the skills of the best human hackers, with thousands of copies searching for and exploiting weaknesses in parallel.
Attackers will become more willing to lean on AI agents as their primary operators, soon giving rise to “copycats, hybrid architectures, and multiple frontier models chained together to run complex, multi-stage operations with almost no human friction.
Chris Cochran, Senior Advisor at SANS Institute
The offense-defense balance may be shifting.
Many have asked themselves why a Chinese actor would use American AI models for their operation, increasing detection risk. Two possible explanations:
This is just one of many campaigns—others use Chinese or open-weight models.
American models are more capable (Epoch AI estimates that open-weight models like DeepSeek-R1 lag state-of-the-art by ~3 months).
Neither answer is reassuring: both mean capabilities are proliferating quickly, likely faster than defenses can adapt.
For an allegedly state-backed actor with significant resources, the impact today appears marginal — more a proof-of-concept. But it clearly marks a trajectory toward far more automated and aggressive operations. The real uplift may emerge when this autonomy and AI misuse trickles down to less-resourced groups, meaningfully expanding their capabilities.
Sevan Hayrapet, Security Researcher at 0labs
AI can help build robust cyber defenses.
The espionage campaign prompted Anthropic to expand its early detection systems, share intelligence with affected entities, and develop new techniques for investigating and mitigating the operation. Frontier AI companies are exploring new ways in which their systems can support cybersecurity. Anthropic, Google, and OpenAI have all encouraged the use of AI to:
conduct automated security reviews
support ongoing threat intelligence
generate patches for identified vulnerabilities
enable rapid incident response
Indeed, AI may still give defenders some advantages: it enables continuous monitoring and management, while attackers are constrained by time, limited visibility, and the need to evade all detection.
Policy action is important to prevent larger cyberattacks.
Private efforts alone may not be sufficient—public oversight can help ensure defenders stay ahead, and governments are beginning to respond. For instance, the U.S. AI Action Plan proposes:
An AI Information Sharing and Analysis Center
Continuous guidance on AI-specific threats
Integration of AI considerations into incident response frameworks
But more ambitious approaches may be warranted:
The Institute for AI Policy and Strategy suggests differential access to frontier AI systems as a way to restrict higher-risk capabilities to selected defenders.
The Institute for Progress suggests launching national R&D projects that “leverage AI to find and fix vulnerabilities in open-source code.”
AI could threaten or protect our critical infrastructure. The right policies can turn it into a shield, but only if we act urgently.
Learn more on our platform:
Overview of cyber offense, including attack orchestration as a distinct AI capability.
Database of cyber operations, including early examples of agentic AI being leveraged in real-world attacks.
Threat Watch, showing a recent increase in the sophistication of AI-enabled cyber operations.


