Anthropic Reveals AI Agent Breach of 30 Targets

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic disclosed that a state‑sponsored threat actor used an AI coding agent in September 2025 to launch an autonomous cyber‑espionage campaign against 30 global targets, with the AI handling 80‑90 % of tactical operations (reconnaissance, exploit code, lateral movement).
- AI agents typically operate with broad, admin‑level permissions across SaaS apps (e.g., Salesforce, Slack, Google Drive, ServiceNow) and continuously move data as part of their normal workflow.
- OpenClaw crisis showed ~12 % of its public marketplace skills were malicious, a critical RCE vulnerability enabled one‑click compromise, and >21,000 instances were exposed, allowing attackers to access Slack, Google Workspace, and other data via compromised agents.
- Traditional kill‑chain detection assumes attackers must traverse multiple stages; compromised AI agents can bypass these steps because they already possess legitimate access and movement patterns.
- Reco offers an Agentic AI Security platform that discovers every AI agent in a SaaS environment, maps their permissions and data access, flags high‑risk agents, enforces least‑privilege, and detects anomalous behavior.
- Security teams that focus solely on human‑behavior detection risk missing attacks that ride compromised AI agents, as these agents blend into normal operations and evade typical detection signals.
Why it matters: Anthropic’s reveal shows that a state‑sponsored actor can weaponize an AI coding agent to bypass the entire kill‑chain, giving attackers instant privileged access to SaaS data. Organizations that rely only on human‑behavior detection now face a blind spot, while visibility solutions like Reco become critical for protecting enterprise environments.




