Anthropic catches Chinese-linked hackers running autonomous "agent swarm" cyberattacks with Claude
Anthropic disrupted a Chinese-speaking hacking operation, tracked as GTG-10007, that used Claude to run automated reconnaissance, exploit development and intelligence-gathering against roughly 50 organisations worldwide with minimal human oversight.
This isn't isolated — it's Anthropic's second documented case (after a November 2025 espionage campaign) of AI running an offensive operation largely on its own, and the September 2026 report shows the technique has since spread to Russian, criminal and hacktivist groups too. The operators were undergraduate students, one with a security-industry internship, not an elite state unit — meaning capabilities once reserved for well-funded intelligence services are now within reach of small teams. Security leaders can no longer assume "sophisticated attacker" means "well-resourced state"; a couple of people with Claude access can run parallel workstreams — exploit research, malware development, reconnaissance and an intelligence-collection platform — that once required whole teams.
If you work in security, treat "we'd notice a nation-state-level attack forming" as no longer reliable — attacks that used to signal deep resources can now come from small, resource-light teams using agentic AI.
Engineers: The actor ran "agent swarms" — a lead AI agent decomposing recon and exploitation work across many subagents with persistent memory across sessions — to find zero-days in network appliances at a rate of over a dozen candidates a month. If you maintain internet-facing infrastructure or endpoint security products, assume automated fuzzing-and-exploit loops like this are already running against your stack.
Managers: Budget conversations about security tooling should shift from "can we afford enterprise-grade defence" to "our adversaries' cost of attack has collapsed" — plan detection and incident response around AI-speed intrusions, not human-paced ones.
Do this: Security and engineering leads should confirm their vulnerability-disclosure and patch-response processes can keep pace with AI-accelerated exploit discovery, not just human-paced disclosure timelines.