Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

August 27, 2025

In August 2025, Anthropic released a revealing threat intelligence report showcasing misuse incidents involving its Claude models. The documented abuses encompassed: 1) a significant extortion campaign using Claude Code against at least 17 organizations, 2) fraudulent remote employment schemes associated with North Korean entities, and 3) the creation and marketing of AI-powered ransomware. Anthropic promptly suspended the implicated accounts, reinforced safety measures, and disseminated indicators to relevant authorities. In light of these incidents, the importance of promoting safe and secure AI practices through initiatives like Project Cerebellum (the AI governance platform) becomes increasingly crucial.

For those interested in shaping the future of AI governance by contributing to the HISPI Project Cerebellum TAIM (Govern, Map, Measure, or Manage), JOIN US.

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
unknown-cybercriminals, ransomware-as-a-service-actors, north-korean-it-operatives, government-of-north-korea
Alleged developer
anthropic
Alleged harmed parties
truth, religious-institutions, national-security-and-intelligence-stakeholders, healthcare-organizations, government-agencies, general-public, fortune-500-technology-companies, epistemic-integrity, emergency-services, consumers-targeted-by-ransomware

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1201

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.