Live data from Hacker News

Disrupting the first reported AI-orchestrated cyber espionage campaign

anthropic.com

211–220 of 298 posts

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#211
Sounds like a psyop

The "disruption" story is a cover: makes them look like defenders while they spy on every programming lab on Earth

In reality, they are the perpetrators:

https://xcancel.com/MaziyarPanahi/status/1988908359378993295

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#212
post #176

The threat actor—whom we assess with high confidence was a Chinese state-sponsored group—manipulated Not surprised at all if this is true, but how can they be sure? Access log? They have extraordinary security team? Or some help from three letter agencies?

My question is: how do they know they're from China and not some other country and just appear to be in China? It seems a good way to distract from the real source and to cause division between your adversaries.

That's a whole area called "attribution". There's usually lots of breadcrumbs and people taking to each other about their findings. It goes down to silly things like many state sponsored hackers working 9-5. And having the right keyboard layout. And using the same version of something as another known group. And accidentally once including a file path that reveals a tiny bit of information. And using the same key in two places that connects them. And...

Or course a lot of that can be spoofed, but you may still slip up. That's why they talk about high confidence.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#213
post #176

Earlier quoted context omitted.

My question is: how do they know they're from China and not some other country and just appear to be in China? It seems a good way to distract from the real source and to cause division between your adversaries.

Short version: they can’t. Just like with a lot of “CIA-style” espionage claims, the “evidence” is usually an IP that resolves to somewhere in China. That’s it. No magic, and not exactly convincing.

I imagine Anthropic employs a lot of talent from China. Beyond the political, they should be fairly certain to publish these claims to avoid an internal shit storm.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#214
post #169

Anyone using Claude for processing sensitive information should be wondering how often it ends up in front of a humans eyes as a false positive

How is your comment related to this article?

It looks like Anrhropic has great visibility into what hackers do. Why would it also see what legitimate users do?

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#215
post #75

After Anthropic "disrupted" these attackers, I'm sure they gave up and didn't try using another LLM provider to do the exact same thing.

Yeah, just take all those MCP servers elsewhere.

MCP is not the only tool calling protocol. And once you write the implementations they're trivial to port to something else.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#216
post #139
post #137

China needs to understand that this kind of espionage is a declaration of war

It's not. Countries have been hacking each other for a while.

This isn't a matter of opinion. No country that respects national sovereignty would do this. Are you alleging that America hacks China as some sort of defense? Or are you trying to normalize these horrendous affronts to human dignity? Both are shameful.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#217

I think as AI gets smarter, defenders should start assembling systems how NixOS does it. Defenders should not have to engage in an costly and error-prone search of truth about what's actually deployed. Systems should be composed from building blocks, the security of which can be audited largely independently, verifiably linking all of the source code, patches etc to some form of hardware attestation of the running sy…

This could be worse, too. With more machines being identical, the same security hole reliably shows up everywhere (albeit not necessarily at the same time). Sometimes the heterogeny impedes attackers.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#218

> At this point they had to convince Claude—which is extensively trained to avoid harmful behaviors—to engage in the attack. They did so by jailbreaking it, effectively tricking it to bypass its guardrails. They broke down their attacks into small, seemingly innocent tasks that Claude would execute without being provided the full context of their malicious purpose. They also told Claude that it was an employee of a l…

I really think we should stop using the term ‘guard rails’ as it implies a level of control that really doesn’t exist.

These things are polite suggestions at best and it’s very misleading to people that do not understand the technology - I’ve got business people saying that using LLMs to process sensitive data is fine because there are “guardrails” in place - we need to make it clear that these kinds of vulnerabilities are inherent in the way gen AI works and you can’t get round that by asking them nicely

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#220

> The threat actor—whom we assess with high confidence was a Chinese state-sponsored group—manipulated our Claude Code tool into attempting infiltration into roughly thirty global targets and succeeded in a small number of cases.

So why do we never hear of US sponsored hackers attacking foreign businesses? Or Swedish cyber criminals? Does it never happen? Are “Chinese” hackers just the only ones getting the blame?

Is it possible that you're biased and assume since China does this that the US also hacks private corporations?
Post reply on HN