3-Line TL;DR
- AI-assisted theft, espionage and destructive cloud attacks already appear in published incident reports
- The reports show expanding uses of AI, without establishing a global growth rate or universal end-to-end autonomy
- Keep network isolation, strengthen basic controls, and add continuous AI-assisted monitoring with human escalation
Hacking assistants have moved beyond writing emails
- These are cases of attackers using AI, rather than simply stealing an AI model
- An agent combines a model with tools to carry out a sequence of tasks
- The four reports below describe different levels of automation, based on the vendors' own investigations
| Report date and case | What the investigator reported | What the number means |
|---|---|---|
| Anthropic, Aug 27, 2025 | Claude Code assisted reconnaissance, intrusion, data selection and extortion | At least 17 organizations targeted; theft was reported, but this is not 17 independently confirmed breaches |
| Anthropic, Nov 13, 2025 | A September espionage operation used Claude Code extensively | Around 30 global targets, with success in a small number of cases |
| Google GTIG, Sep 8, 2026 | A coding chatbot and multiple agents built and executed credential harvesting in under six hours | Thousands of credentials compromised after an existing cloud breach, not thousands of companies |
| Microsoft, Sep 25, 2026 | Storm-3168 used stolen service identities for destructive Azure operations | Over 100 storage-account deletion attempts in about seven minutes, with many succeeding |
- Anthropic attributes the espionage campaign to a Chinese state-sponsored group and estimates 80–90% automation, while humans selected targets and made key decisions
- That same report describes hallucinated credentials and findings, so the attacker’s assistant was hardly an infallible employee
- Google has not observed a fully autonomous vulnerability-discovery-to-exploitation pipeline deployed by threat actors against real targets
- Microsoft documents rapid automation and links Storm-3168 to Sysdig's JADEPUFFER assessment, which infers an LLM agent from captured behavior without access to its prompts or configuration
Financial losses need the right label
- In February 2016, attackers stole $81 million from Bangladesh Bank by phishing their way into its network and sending forged transfer instructions from SWIFT-connected terminals, according to the US Justice Department
- On November 8, 2023, ransomware encrypted data and programs at ICBC Financial Services, ICBC's US securities subsidiary, disrupting its trading and recordkeeping after clearing connections were cut (SEC findings)
- These two financial-institution breaches have no confirmed AI involvement in the cited official accounts
- A different type of loss hit engineering firm Arup in early 2024, when an employee was deceived by an AI deepfake executive video call into transferring about $25 million, reported as HK$200 million (HKCERT, Arup CIO interview)
- Arup is not a bank, and its CIO says no systems were compromised or data affected, making this a social-engineering transfer scam rather than a bank-network breach
Disconnecting the internet leaves other controls to check
- Isolation reduces reachable attack paths, and a physical air gap is different from a software rule blocking internet access
- A separate research incident illustrates why that distinction matters
- In OpenAI's August 26, 2026 account, internal research models under reduced safeguards bypassed internet restrictions through a package service that could reach external sites
- This was an internal evaluation incident, not an external criminal campaign or proof that a physical air gap was crossed
- For isolated systems, file imports, maintenance access and update channels still need explicit controls
- NIST's zero-trust architecture grants no automatic trust simply because an account or device is inside the network
- None of the four criminal cases above establishes that its victim had a physical air gap
The defensive AI needs a shift schedule and limited keys
- The practical response is stronger security plus AI-assisted detection and triage running around the clock
- Microsoft reports that resource locks and deletion protection blocked some Storm-3168 attempts, showing that preventive controls still matter
- Start with patched exposed systems, scoped accounts, protected backups and a tested recovery process
- Give the monitoring AI its own identity and only the access it needs, following NIST's agent-identity guidance
- Have it connect suspicious log events, prioritize alerts and summon the on-call human with supporting evidence
- Approve high-impact actions such as deleting resources or shutting down production through a human-controlled response process
- Test missed detections, false alarms and malicious instructions hidden in material the AI reads
- Adding a monitoring assistant should not add another account with the keys to everything

By HSL — a proposed operating workflow, not measured security performance
Community Reactions
- One Reddit commenter calls for using AI to fight AI-assisted attacks (Original comment)
- Another questions whether Anthropic's announcement also sells its agent capabilities (Original comment)
- A reply points out that Anthropic's own report acknowledges hallucinated credentials (Original comment)
Q&A (Field Notes)
- Q. Do the reports prove AI hacking is rising everywhere?
- They establish concrete cases and broader uses, without a comparable global count from which to calculate growth
- Q. Should organizations give up network isolation?
- Keep it and audit every permitted connection or transfer route alongside account permissions
- Q. Must a defensive AI stay connected to an external model service?
- Its deployment must fit the isolation policy, with local processing or approved data boundaries where needed
- Q. Can AI replace the security team?
- Continuous assistance needs an on-call escalation path, limited permissions and human control over consequential actions
