← All articles
News21 July 20265 min read

AI-Driven Cyberattacks: What the Anthropic Case Means for Small and Medium-Sized Businesses

In November 2025, Anthropic disclosed an espionage campaign in which an AI tool carried out large parts of the attacks itself. What the case really shows and which protective measures matter now.

What happened: the case in brief

In mid-September 2025, the AI company Anthropic, developer of the language model Claude, noticed suspicious activity in its systems. The subsequent investigation found that an attacker group, which Anthropic attributes with high confidence to Chinese state sponsorship and internally calls GTG-1002, had misused the tool Claude Code. Claude Code is what is known as an agentic AI tool: an AI that does not just answer questions but independently plans and executes work steps, for example starting programs and evaluating their results.

According to Anthropic, the campaign targeted around 30 organizations worldwide, including large technology companies, financial institutions, chemical companies, and government agencies. In a small number of cases, the intrusion actually succeeded. Anthropic blocked the accounts involved, informed affected organizations, cooperated with authorities, and published a report on the incident on November 13, 2025.

Important for context: the figures and the sequence of events come from Anthropic’s own report. Independent confirmation exists only to a limited extent so far. More on that later.

How the attackers misused the AI

Modern AI services have safeguards that reject obviously harmful requests. The attackers bypassed them with two simple tricks. First, they posed to the AI as employees of a legitimate IT security firm that was supposedly conducting defensive tests. Second, they broke the attack down into many small subtasks that look harmless when viewed individually, such as checking a single server for open access points.

Equipped this way, the AI took over large parts of the attack: reconnaissance of the targets, meaning the question of which systems are reachable from the outside, the search for vulnerabilities, the collection of access credentials, the movement from system to system within the network, known in technical terms as lateral movement, and finally the exfiltration of data.

What is remarkable is what was used: freely available standard tools for penetration testing, known for years, that is, for the controlled probing of systems for vulnerabilities. The AI did not invent any new attack techniques. It orchestrated existing tools, meaning it called them, combined them, and evaluated their output automatically.

What is new here: the degree of automation

What is new about the case is not the what but the how much. According to Anthropic, the AI handled 80 to 90 percent of the campaign work. Human attackers intervened at only four to six decision points per campaign, for example when approving the actual intrusion or selecting the data to steal. At peak times, the system issued thousands of requests, often several per second, a pace that a human team cannot sustain.

For the threat landscape, this means one thing above all: attacks are becoming cheaper. What used to occupy a well-practiced team for days or weeks can now be attempted with less staff in less time. Falling costs per attack attempt mean that it pays off for attackers to probe more targets, including those previously considered too small or too unattractive. This is exactly the point at which the case becomes relevant for small and medium-sized businesses.

What is not new: the entry points remain the same

As remarkable as the degree of automation is, the paths into the network were the same as they have been for years. What was exploited were services reachable from the outside, known vulnerabilities, and stolen access credentials. None of these methods requires AI, and none of them leaves you powerless. If you install security updates promptly, use multi-factor authentication, meaning a second confirmation required in addition to the password, and know which of your systems are reachable from the outside, you are working on exactly the points that are also effective against AI-supported attacks.

This matches the assessment of the BSI (Germany’s Federal Office for Information Security). Its 2025 situation report describes a threat landscape that remains tense and observes that attackers prefer to seek out targets with weak basic security. Automation amplifies this effect: those who are easy to find and easy to hit get hit more often.

An honest assessment: what the case proves and what it does not

An honest assessment has to include this: the account comes from Anthropic itself, and independent security researchers have voiced criticism. The main complaint is that Anthropic has not published any indicators of compromise, meaning technical traces such as network addresses or file characteristics that would allow other companies to detect the attacks and verify the claims. Some researchers therefore consider the reported degree of autonomy insufficiently substantiated.

Anthropic itself also names limitations: at times the AI invented access credentials that did not work and classified publicly available information as supposedly secret findings. Such hallucinations, meaning convincing-sounding but false outputs of an AI system, still hold back fully autonomous attacks for now.

For your day-to-day practice, this debate changes little. Even if you read the figures conservatively, the core remains undisputed: AI tools noticeably lower the effort and cost of attacks. Panic is not warranted, but neither is waiting.

What you should do now, in concrete terms

The effective measures are well known and largely a matter of craft. Check the following points in your company: Security updates are installed promptly, within a few days for critical vulnerabilities. Multi-factor authentication is active everywhere systems are reachable from the outside, especially for email, VPN access, meaning encrypted access into the company network, and administrator accounts. An up-to-date list of all externally reachable systems and services exists. Backups follow the 3-2-1 rule, meaning three copies on two different media, one of them off site or offline, and restoring from them has actually been tested. Administrator rights are restricted to the people who really need them.

Much of this you can implement yourself. Activating multi-factor authentication, defining update routines, maintaining a system list, and testing restores takes discipline above all, not specialist knowledge. External help makes sense where continuous operation or specialist expertise is required: analyzing your own attack surface from the outside, ongoing monitoring, meaning the automatic surveillance of your systems for suspicious activity, and creating and rehearsing an emergency plan.

A final point concerns your own use of AI. Define which employees may use which AI services with which company data. The case shows how capable agentic AI tools have become. That applies in both directions.

The short version

The Anthropic case shows that AI makes attacks faster and cheaper, but not magical: the entry points remain the same, and the well-known basic measures still work. If you run updates, multi-factor authentication, backups, and monitoring properly, you have already done the largest part of the defense. If you would like support with this, Ruknova, based in Schwerin, is here to help, working Germany-wide and available Mon-Fri from 8 am to 4 pm.