← Incident database

anthropic-claude-code-abuse-2025 · Disclosed 2025-11-13

Claude Code: attacker misuse in a multi-organization intrusion campaign

Anthropic reported attacker use of Claude Code for reconnaissance, exploit development, credential harvesting, and exfiltration. About 30 organizations were targeted, with success reported at a small number.

CredentialsCause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Anthropic reports investigating attacker misuse of Claude Code in an observed campaign, distinct from evaluation incidents.

    [s1]Introduction / How the cyberattack worked
  • Reported fact

    Human operators selected targets and disguised fragmented tasks as defensive testing; Anthropic describes AI assistance through reconnaissance and exfiltration.

    [s1]How the cyberattack worked

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Anthropic reported banning accounts, notifying affected organizations, coordinating with authorities, and improving safeguards.

    [s1]Introduction

Evidence relevant to prevention

Insufficient evidence

Victim-specific entry causes are unspecified; inspect credential reach, access logs, and permissions of AI operated in your own environment.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementReported fact

Anthropic reports attacker use of Claude Code; this does not establish unavoidable victim vulnerabilities or a population-wide increase in AI attacks.

Victim names, vulnerabilities, CVEs, and precise entry dates are undisclosed; target count is not victim count, and autonomy assessments are the investigator’s interpretation.

Sources

  1. [s1] Anthropic · Primary source

    Disrupting an AI-orchestrated cyber espionage campaign ↗

    Published 2025-11-13 · Reviewed 2026-10-02