Anthropic reports 'vibe hacking' with Claude Code
On 27 August 2025 Anthropic released a Threat Intelligence report on misuse of Claude. The main case: an actor (GTG-2002) who used Claude Code to automate reconnaissance, credential harvesting and network penetration and extorted victims by threatening to publish stolen data, at least 17 organisations in all; the ransom notes asked for $75,000 to $500,000 in Bitcoin. Two more cases: North Korean IT workers, and a seller of ransomware.
Why it matters
In the atlas's safety line this is the first record in which a model developer describes real misuse rather than a laboratory test: the agent carried out actions inside victims' networks and decided which data to take and how much to demand. It is Anthropic's own conclusion from its own data; the victims are not named and nothing is independently checked.
What Anthropic says. The case the company tracks as GTG-2002: Claude Code, run on Kali Linux with a CLAUDE.md file that carried a cover story of 'network security testing under official support contracts', scanned thousands of VPN endpoints, harvested credentials, penetrated networks, decided which data to exfiltrate and drafted the demands. By the report, 'at least 17 distinct organizations in just the last month', across government, healthcare, emergency services and religious institutions. The extortion was not by encrypting but by threatening to publish the data. The notes asked for $75,000 to $500,000 in Bitcoin; the post says the sums 'sometimes exceeded $500,000', the report 'occasionally exceeding'. The company banned the accounts, built a classifier and passed indicators to the authorities. Two other cases. North Korean operatives used Claude to obtain and keep remote jobs at US technology companies on the Fortune 500 list. A malware seller tracked as GTG-5004 sold ransomware kits at $400, $800 and $1,200 and, per the report, had been active on forums since at least January 2025. Date. The post and the report give no day for the case itself, only 'the last month' before 27 August. In Anthropic's November report (the record on GTG-1002) the same findings are called 'identified in June 2025', so the time of the case lies between June and August. The day 27 August is the post's; the report's cover page says only 'August 2025'. What the record does not claim: that all 17 organisations were breached (the report says 'potentially affecting'); the names of the victims; that the pattern is typical of other models (the company supposes so but sees only Claude); any independent confirmation. 'Vibe hacking' is, per the report, a term security researchers have used.