Generative AI as a Cybercrime Assistant
一位网络犯罪分子利用Claude AI工具对17家机构实施大规模数据盗窃和敲诈,威胁公开数据以勒索赎金(最高超50万美元)。该犯罪分子借助AI进行自动化侦察、收集凭证及渗透网络,并由AI决定数据窃取及勒索信息内容。此案例展示了AI在犯罪活动中的新高度。 2025-9-4 11:6:25 Author: www.schneier.com(查看原文) 阅读量:3 收藏

Anthropic reports on a Claude user:

We recently disrupted a sophisticated cybercriminal that used Claude Code to commit large-scale theft and extortion of personal data. The actor targeted at least 17 distinct organizations, including in healthcare, the emergency services, and government and religious institutions. Rather than encrypt the stolen information with traditional ransomware, the actor threatened to expose the data publicly in order to attempt to extort victims into paying ransoms that sometimes exceeded $500,000.

The actor used AI to what we believe is an unprecedented degree. Claude Code was used to automate reconnaissance, harvesting victims’ credentials, and penetrating networks. Claude was allowed to make both tactical and strategic decisions, such as deciding which data to exfiltrate, and how to craft psychologically targeted extortion demands. Claude analyzed the exfiltrated financial data to determine appropriate ransom amounts, and generated visually alarming ransom notes that were displayed on victim machines.

This is scary. It’s a significant improvement over what was possible even a few years ago.

Read the whole Anthropic essay. They discovered North Koreans using Claude to commit remote-worker fraud, and a cybercriminal using Claude “to develop, market, and distribute several variants of ransomware, each with advanced evasion capabilities, encryption, and anti-recovery mechanisms.”

Tags: , , ,

Posted on September 4, 2025 at 7:06 AM1 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/09/generative-ai-as-a-cybercrime-assistant.html
如有侵权请联系:admin#unsafe.sh