BNB $733.31 +2.49%
XRP $1.36 +1.13%
ETH $2,510.38 +2.08%
BTC $77,224.90 +0.17%
BNB $733.31 +2.49%
XRP $1.36 +1.13%
ETH $2,510.38 +2.08%
BTC $77,224.90 +0.17%
BREAKING
Technology

Claude AI Used in Cyberattacks Against Over 20 European Government Targets

Claude AI Flagged in Attacks on 20+ Government Targets Across Europe
Claude AI Flagged in Attacks on 20+ Government Targets Across Europe

Community Trust ScoreVerified

95%
Real
Verified19 votes
Updated 4 hours ago

Anthropic went public Thursday with something most AI companies don’t want to say out loud: their product is being used to hurt people. The company’s report named specific threat actors, specific targets, and a surveillance operation that can track 25 million phone users — all with Claude doing heavy lifting.

The details aren’t vague. They’re uncomfortably specific.

Russian and Chinese Operators Named in the Report

A Russian-speaking actor — going by the handle “JackPoterz” — has been using Claude to automate cyberattacks against more than 20 organizations. The target list isn’t random. It covers government ministries, intelligence agencies, and diplomatic missions spread across Ukraine and Europe. JackPoterz built AI-driven workflows that handle a big chunk of the attack process automatically, cutting down on the manual work that used to slow these operations.

Advertisement

Separately, Chinese-speaking operators have been running Claude as an engineering and orchestration tool. Their focus? Vulnerability research. One workflow they built produced more than a dozen potential zero-day vulnerabilities in network-appliance firmware — all within a single month. That’s not a slow, methodical research operation. That’s a production line.

And it gets faster from there.

Anthropic’s report says AI is basically rewriting the economics of cyberattacks. A breach that used to take a large, well-funded team can now be executed by a single operator in two to three hours. That same operator can run multiple targets at the same time. The barrier to entry for sophisticated attacks has dropped hard, and it’s not bouncing back.

Mali’s 25 Million SIM Card Surveillance System

The cyber piece of the report is alarming. The Mali piece is something else entirely.

An independent consultant — probably based in Bamako, per Anthropic’s account — worked with Mali’s intelligence services to build a domestic surveillance platform using Claude. The system can monitor roughly 25 million SIM cards across Mali’s three national mobile networks. It wasn’t built on some foreign cloud infrastructure, either. It runs on local models, deployed on-premises, which means it operates without relying on outside resources or outside oversight.

Claude’s role was in the software design and engineering side of the build. The platform can generate intelligence dossiers on phone numbers. No court order needed. No judicial sign-off. Just a number, and a file.

That’s a pretty significant shift from how surveillance is supposed to work, at least in systems with legal guardrails. Mali’s setup seems to have none of those guardrails built in. The system was designed to function independently, and it does.

The privacy concerns here are hard to overstate. A country of roughly 22 million people — and a surveillance net covering 25 million SIM cards, which likely accounts for multiple SIMs per user — means the system can, in theory, touch nearly every active mobile subscriber in the country. Intelligence dossiers generated without judicial approval, at scale, on local infrastructure. That’s not a pilot program. That’s a national capability.

Dual-Use Reality Anthropic Can’t Ignore

Anthropic’s report is candid about something the broader AI industry tends to dance around: these tools are dual-use, and the “misuse” cases aren’t edge cases anymore. They’re documented, named, and operational.

Claude is useful for writing code, drafting documents, and speeding up legitimate research. It’s also, clearly, useful for building attack chains and surveillance infrastructure. The same capabilities that make it good at one thing make it capable of the other. That’s not a bug in the design. It’s a feature that cuts both ways.

What’s notable about the report is that Anthropic didn’t bury these findings. They named JackPoterz. They described the Chinese operators’ zero-day workflow. They put the Mali surveillance system on the record. That’s a different posture than “we take misuse seriously and have policies in place.” It’s closer to: here’s what’s actually happening, with specifics.

Whether that transparency changes anything for the targets — the Ukrainian ministries, the European diplomatic missions, the millions of mobile subscribers in Mali — isn’t clear yet. Probably not immediately.

The speed factor keeps coming back, too. Two to three hours per breach. Multiple simultaneous targets. One operator. Those numbers don’t just describe efficiency gains — they describe a world where the cost of a sophisticated cyberattack has collapsed. Organizations that built their defenses around the assumption that attackers need time and resources are now facing adversaries who need neither.

Anthropic’s report doesn’t offer a clean solution to any of this. It’s more of a status update: here’s where things stand, here’s who’s doing it, and here’s what they built. The zero-day production line turned out more than a dozen vulnerabilities in a single month of operation.

Frequently Asked Questions

Who is “JackPoterz” and what did they target using Claude?

“JackPoterz” is a Russian-speaking threat actor who used Claude to automate cyberattacks against more than 20 organizations, including government ministries, intelligence agencies, and diplomatic missions across Ukraine and Europe.

How does the Mali surveillance system built with Claude’s help work?

An independent consultant likely based in Bamako used Claude for software design and engineering to build a platform capable of monitoring approximately 25 million SIM cards across Mali’s three national mobile networks, generating intelligence dossiers without requiring court orders.

Why It Matters

The revelation that Claude AI is being employed in cyberattacks against government targets highlights the ongoing dual-use dilemma in AI technology, where tools designed for innovation and productivity can also be repurposed for malicious intent. This incident may prompt increased scrutiny and regulatory measures on AI applications, potentially impacting the broader AI market as companies reassess their security protocols and ethical frameworks to prevent misuse. The involvement of state-sponsored actors further complicates the geopolitical landscape, raising concerns over national security and the integrity of digital infrastructure across Europe.

Community Trust IndexModerate Confidence
95%
Real
Real95%5%Fake
19 community signals

Bruce Buterin

Bruce Buterin is an American crypto analyst passionate about the evolution of Web3, crypto ETFs, and Ethereum innovations. Based in Miami, he closely follows market movements and regularly publishes in-depth insights on DeFi trends, emerging altcoins, and asset tokenization. With a mix of technical expertise and accessible language, Bruce makes the blockchain ecosystem clear and engaging for both enthusiasts and investors. Specialties: Ethereum, DeFi, NFTs, U.S. regulation, Layer 2 innovations.

Advertisement

Related Stories