Read The Times Australia

Daily Bulletin

An AI lab says Chinese-backed bots are running cyber espionage attacks. Experts have questions

  • Written by: Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne
An AI lab says Chinese-backed bots are running cyber espionage attacks. Experts have questions

Over the past weekend, the US AI lab Anthropic published a report about its discovery of the “first reported AI-orchestrated cyber espionage campaign”.

The company says a Chinese government–sponsored hacking group used Anthropic’s own Claude AI tool to automate a significant part of an effort to steal sensitive information from around 30 organisations.

The report has drawn a lot of attention. Some, including respected experts, have warned that AI-automated cyber attacks are the future, urging cyber defenders to invest now before the coming onslaught.

At the same time, many in the cyber security industry have been underwhelmed by Anthropic’s claims, saying the actual role AI played in the attacks is unclear.

What Anthropic says happened

Critics have pointed out what they say is a lack of detail in the report, which means we have to do a certain amount of guesswork to try to piece together what might have happened. With that in mind, it appears the hackers built a framework for carrying out cyber intrusion campaigns mostly automatically.

The grunt work was carried by Anthropic’s Claude Code AI coding agent. Claude Code is designed to automate computer programming tasks, but it can also be used to automate other computer activities.

Claude Code has built-in safety guardrails to prevent it from causing harm. For example, I asked it just now to write me a program that I could use to carry out hacking activities. It bluntly refused.

However, as we have known from the very first days of ChatGPT, one way to bypass guardrails in AI systems is to trick them into engaging in role-play.

Anthropic reports that this is what these hackers did. They tricked Claude Code into believing it was assisting authorised hackers to test the quality of a system’s defences.

Missing details

The information Anthropic has published lacks the fine details that the best cyber incident investigation reports tend to include.

Chief among these are so-called indicators of compromise (or IoCs). When investigators publish a report into a cyber intrusion, they usually include hard evidence that other cyber defenders can use to look for signs of the same attack.

Each attack campaign might use specific attack tools, or might be carried out from specific computers under the attacker’s control. Each of these indicators would form part of the cyber intrusion’s signature.

Somebody else who gets attacked using the same tools, coming from the same attacking computers, can infer that they have also been a victim of this same campaign.

For example, the US government Cybersecurity and Infrastructure Security Agency recently partnered with government cyber agencies worldwide to publish information about ongoing Chinese state-sponsored cyber espionage, including detailed indicators of compromise.

Unfortunately, Anthropic’s report includes no such indicators. As a result, defenders are unable to determine whether they might also have been victims of this AI-powered hacking campaign.

Unsurprising – and with limited success

Another reason many have been underwhelmed by Anthropic’s claims is that, on their face and absent hard details, they are not especially surprising.

Claude Code is widely used by many programmers because it helps them to be more productive.

While not exactly the same as programming tasks, many common tasks performed during a cyber intrusion are similar enough to programming tasks that Claude Code should be able to carry them out, too.

A final reason to be wary of Anthropic’s claims is that they suggest the attackers might have been able to get Claude Code to perform these tasks more reliably than it typically does so.

Generative AI can perform marvellous feats. But getting systems such as ChatGPT or Claude Code to do so reliably remains a major challenge.

In the memorable words of one commentator, too often these tools respond to difficult requests with “ass-kissing, stonewalling, and acid trips”. In plainer language, AI tools are prone to sycophancy, repeated refusal to carry out difficult tasks, and hallucinations.

Indeed, Anthropic’s report notes that Claude Code frequently lied to the attackers, pretending it had carried out a task successfully even when it hadn’t. This is a classic case of AI hallucination.

Perhaps this explain the attack’s low success rate: Anthropic’s own reporting says that while about 30 organisations were targeted, the hackers succeeded against only a few.

What does this mean for the future of cyber security and AI?

Whatever the details of this particular campaign, AI-enabled cyber attacks are here to stay.

Even if one contends that current AI-enabled hacking is lame, it would be foolish for cyber defenders to assume it will stay that way.

If nothing else, Anthropic’s report is a timely reminder for organisations to invest in cyber security. Those who do not may face a future in which their secrets are stolen or operations disrupted by autonomous AI agents.

Authors: Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne

Read more https://theconversation.com/an-ai-lab-says-chinese-backed-bots-are-running-cyber-espionage-attacks-experts-have-questions-269815

Business News

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...