AI-Powered Extortion

Vibe Hacking: Hacker Uses Claude Code to Extort Companies

Claude Code, vibe hacking, AI hacking, Claude Code cyber extortion campaign, Anthropic vibe hacking report, hacker uses Claude Code for extortion
Facebook
X
LinkedIn
Reddit
WhatsApp

Anthropic uncovered a case in 2025 in which a hacker used Claude Code to automate almost the entire operation of an extortion campaign.

In August 2025, Anthropic disclosed in its own threat report that it had stopped a cybercriminal who, according to the company, had used the coding tool Claude Code “at an unprecedented scale” in a large-scale extortion campaign. Anthropic refers to the underlying approach as “vibe hacking” and tracks the case internally as GTG-2002.

Ad

At Least 17 Organizations Targeted

According to Anthropic, at least 17 organizations were affected by the campaign, including entities in healthcare, emergency services, government and religious institutions. Rather than encrypting stolen data with conventional ransomware, the attacker threatened to publish the information unless the targeted organizations paid a ransom.

Claude Also Made Strategic Decisions

Anthropic says the attacker used Claude Code to automate both reconnaissance of vulnerable targets and the theft of credentials and intrusion into other networks. Claude was also allowed to make tactical and strategic decisions, including determining which data to steal and how to craft psychologically targeted extortion demands.

The model also analyzed the victims’ stolen financial data to determine realistic ransom amounts and generated visually intimidating extortion notes that were displayed on the affected systems.

Ad

How the Operation Worked

According to Jacob Klein, head of threat intelligence at Anthropic, the campaign was likely carried out by a single hacker based outside the United States and continued for around three months.

According to NBC News, the attacker initially instructed Claude Code to identify vulnerable companies. The model then created malware to extract sensitive information from the targeted systems, organized and analyzed the stolen files to assess their value for extortion, and ultimately drafted tailored extortion emails.

Ransom Demands Reached $500,000 USD

According to Anthropic, ransom demands ranged from $75,000 to more than $500,000 USD in some cases, with payments requested in Bitcoin.

Anthropic said it detected and subsequently investigated the suspicious activity. The company mapped the scope of the operation, disabled the associated accounts, notified the affected organizations and coordinated with law enforcement agencies.

The case was part of a broader threat report published by Anthropic in August 2025. The report also described a fraud scheme involving North Korean IT workers who used Claude to falsely secure remote positions at Western companies, as well as the sale of AI-generated ransomware-as-a-service by a cybercriminal with only basic programming skills.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel