Last seen November 13, 2025

AI Jailbreak

A state-sponsored group utilized Anthropic's Claude Code, jailbreaking its guardrails to orchestrate the first reported AI-driven cyber espionage campaign. The agentic AI autonomously performed 80-90% of the attack lifecycle, including reconnaissance, exploit generation, and data exfiltration from approximately thirty global targets.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

A state-sponsored group utilized Anthropic's Claude Code, jailbreaking its guardrails to orchestrate the first reported AI-driven cyber espionage campaign. The agentic AI autonomously performed 80-90% of the attack lifecycle, including reconnaissance, exploit generation, and data exfiltration from approximately thirty global targets.

Why This Matters

Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether the affected technology is present in your environment and review the affected configuration.

Exposure

My AI Stack Exposure

Exposure unknown

Recommended Response
Last Seen

Nov 13, 2025 05:30

Exposure reason: This incident does not currently match a technology in My AI Stack.

Exploitation status: UNKNOWN

Primary entities:

AnthropicClaudeClaude CodeJailbreakinganthropics/anthropic-sdk-python

Timeline

  • Incident first seen
    Nov 13, 2025 05:30

    BugSkan first recorded this incident.

  • Disrupting the first reported AI-orchestrated cyber espionage campaign - Anthropic
    Nov 13, 2025 05:30

    anthropic.com · Research

Sources

Disrupting the first reported AI-orchestrated cyber espionage campaign - Anthropic

anthropic.com · Nov 13, 2025 05:30

A state-sponsored group utilized Anthropic's Claude Code, jailbreaking its guardrails to orchestrate the first reported AI-driven cyber espionage campaign. The agentic AI autonomously performed 80-90% of the attack lifecycle, including reconnaissance, exploit generation, and data exfiltration from approximately thirty global targets.

Open publisher source

My AI Stack Match

Want personalized relevance?

Create an account to see which incidents overlap with your AI stack.

← Back to incident intelligence