Skip to content

Product1 publisher3 min readPublished

Anthropic counted breaches finished in two to three hours by single operators

Anthropic's threat intelligence team spent nine months banning accounts, and its 10 September report keeps landing on the same finding, that one operator now does work that needed a team a year ago.

The Product Desk · Product desk

Illustration accompanying Anthropic counted breaches finished in two to three hours by single operators

What happened

  • Anthropic published a threat intelligence report on 10 September covering nine months of misuse it disrupted, across seven harm areas and involving its Claude Haiku, Sonnet and Opus models.
  • Two people the company described as undergraduate students in Hunan ran what it called agent swarms against roughly fifty organisations, including a Southeast Asian government agency whose citizen records they retrieved.
  • A single subscriber Anthropic assessed as a Bamako-based consultant working with Mali's state intelligence service used Claude to build Lakana 360, which monitored roughly 25 million SIM cards.
  • Anthropic said a religious affairs intelligence unit in China had shrunk from many teams of analysts to a single office producing thousands of investigations a month with an AI assistant.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Anthropic's own framing puts the security budget question on throughput: if a team's worth of intrusion work now fits inside one subscription, analyst hours per incident is the resource that runs out first.
  • constraint Vendor enforcement stops at the subscription. Lakana 360 ran on local models on-premises, and banning the account left the deployed system running.
  • exposure Anthropic says the Mali platform bypassed the legal requirement for a court order before an operator could disclose certain records. That court order was the check those subscribers had.
  • precedent Anthropic's January-to-July surveillance cases include commercial spyware vendors alongside state-aligned actors. Buyers of off-the-shelf spy tooling now have a build path as well as a purchase order.

The Russian-speaking operator Anthropic tracks as GTG-20006 ran a loop any release engineer would recognise. Submit the malware, ask whether security products had flagged it, rebuild it automatically, try again [8]. Anthropic attributed the activity in line with public reporting on the group known as Midnight Blizzard, and said the targets included Ukrainian and European government organisations, with diplomatic and defence bodies among them [7].

Security plans tend to budget for the unrecognisable. The largest section of this report is about the familiar arriving faster, and its central claim is that AI has narrowed the gap between well-resourced state hackers and lone operators [4]. Anthropic said it saw breaches completed in two to three hours, with dozens of victims handled in parallel by single operators [5].

Hold the two-to-three-hour figure. Run those back to back through a full day and one person covers eight to twelve intrusions [3]. The report does not say anyone sustained that pace, and nobody should staff off the arithmetic alone. What it does give is a queue length. A rota built around three or four incidents a week meets a multi-victim campaign as backlog, and every technique in that campaign is one its controls already recognise.

Jacob Klein, who leads threat intelligence at Anthropic, told Axios that AI was making state surveillance cheaper and more efficient, and was not changing who governments target [16]. "They're effectively automating parts of the job within the intel apparatus," he said [17]. He added that the pattern was no longer theoretical. "Authoritarian states are using AI for surveillance, repression and influence operations today," he told Axios [18].

The cheaper-but-familiar reading has one exception inside the report itself. Anthropic called the use of Claude to write software for conventional weapons a new form of misuse, and counted six cases, three in China, two in Russia and one in Yemen [19]. Five of the six sit in China or Russia [2]. That section offers a case count and no comparison with what the same work cost before. For a budget, it carries less weight than the cyber numbers.

The person who has to act on this report owns the on-call rota. Two attributes sort their control list. First, whether the control recognises the technique without a person. Second, whether anything happens before a person acts. The ones that recognise the technique and then wait for a human are where a two-hour intrusion wins, and they are the same ones that read as coverage on a maturity chart. For each detection worth keeping, the number to write down is analyst minutes per event, multiplied by ten. Set it next to the hours the rota actually has.

What to watch

  • Whether Anthropic publishes per-harm-area case counts or account lifetimes, so defenders can size a queue instead of inferring one from breach duration.
  • Whether other model vendors add conventional weapons software as a named harm area in their own misuse reporting.
  • Whether Mali's three mobile operators or any regulator respond to the Lakana 360 findings.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories