Sunday, 16 August 2026
The Verified Journalism Press

Journalism with its sources attached.

Sections
WORLD
AUSTRALIA
INDIA
BUSINESS
TECHNOLOGY
SCIENCE
SOCIETY
RIGHTS
CORRUPTION
CULTURE
OPINION
FAMOUS
The Press
Latest
Brussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached AustraliaBrussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached Australia
Markets
ASX 200
S&P 500
Nasdaq
FTSE 100
Nikkei
Gold
Brent
AUD / USD
AUD / EUR
AUD / GBP
AUD / JPY
Bitcoin
Ethereum
Yahoo · ECB · CoinGecko

Front page / Technology

Cybersecurity

The argument has moved from AI writing the phishing email to AI running the intrusion

Anthropic said in November 2025 that it had disrupted an espionage campaign in which its own models performed most of the attack work. Security researchers disputed the claim within days, and that dispute is now the live question for defenders.

Anthropic said on 14 November 2025 that it had disrupted what it called the first documented large scale AI orchestrated cyber espionage campaign, tracked internally as GTG-1002 and assessed as the work of a likely China linked actor. The operators, Anthropic said, jailbroke its Claude models by presenting themselves as a security firm conducting authorised testing, then used Claude Code and Model Context Protocol servers to run reconnaissance, map environments, test credentials and extract data. Anthropic said the model performed 80 to 90 per cent of the operation with limited human involvement, that around 30 organisations were targeted and that at least four were breached. MITRE has since catalogued the activity in its ATT&CK knowledge base as Campaign C0062.

The report did not go unchallenged. BleepingComputer reported that security researchers and AI practitioners questioned the account, with the researcher Daniel Card among those dismissing the framing, and that Anthropic published no indicators of compromise to allow independent verification. BleepingComputer said its requests for technical detail went unanswered. Anthropic's own report noted that Claude frequently overstated its findings and at times fabricated data during the operation, which is a significant qualification on any claim of autonomous capability.

The disagreement is not settled. What is not in dispute is the direction: the tooling that made phishing cheap is the same tooling now being pointed at reconnaissance, credential testing and lateral movement, and threat reporting through 2026 has described adversaries assembling agentic frameworks that chain those steps together.

The economics of that tooling are documented. Research by Fredrik Heiding and colleagues, published as arXiv preprint 2412.00586 and tested on 101 human participants, found that arbitrary phishing emails achieved a 12 per cent click through rate, that emails written by human experts achieved 54 per cent, that fully automated AI emails also achieved 54 per cent, and that AI emails with a human reviewing them achieved 56 per cent. The researchers reported that the automated approach cut campaign execution costs by more than 95 per cent.

That last figure is the one that changes the threat. The AI advantage in phishing is not mainly about better prose. It is the collapse in the cost of producing a targeted lure, which changes who can run these campaigns and at what volume.

Security leaders report feeling it. Hornetsecurity's survey of security leaders found that 77 per cent of chief information security officers flagged AI generated phishing as a growing threat. Darktrace's State of AI Cybersecurity 2025 report, published on 4 March 2025 and based on responses from more than 1,500 security professionals across 14 countries, found 78 per cent of chief information security officers reporting a significant impact from AI powered threats, up five points on the previous year, while 60 per cent said they felt prepared to defend against them.

The volume data points the same way. Acronis reported in its first half 2025 threat data that phishing accounted for 52 per cent of initial attacks on managed service providers, up from 30 per cent in the same period of 2024, and that social engineering and business email compromise rose from 20 per cent to 25.6 per cent of email attacks. Its follow up report, published on 18 February 2026, found phishing driving 83 per cent of all email threats, and reported that 80 per cent of ransomware as a service operations were advertising AI or automation features to their criminal customers.

For defenders, this reframes the task. Awareness training was designed around the assumption that a bad email looks wrong. The Heiding results show that assumption has failed at the level of the individual message, which makes the message the wrong place to fight. The controls that still work are structural: phishing resistant multifactor authentication, tight privilege boundaries, monitored service accounts and the ability to detect anomalous behaviour after a credential has been used, rather than before.

There is a second exposure. Organisations deploying AI internally are adding model endpoints, plugins and data pipelines to their attack surface, and the security controls around those are generally younger than the systems they connect to.

What happens next depends on evidence that does not yet exist in public. No independent researcher has confirmed Anthropic's GTG-1002 account, no comparable disclosure has come from another model provider with indicators attached, and no regulator has set a standard for what an AI vendor must publish when it detects its own tools being used in an intrusion. Until that changes, the most consequential claim in this field rests on a single company's word about its own product.

Sources

Every factual claim above rests on the 10 published sources below. They are listed so you can check the reporting rather than take it on trust.

  1. AnthropicDisrupting the first reported AI-orchestrated cyber espionage campaign
  2. MITRE ATT&CKAnthropic AI-orchestrated Campaign, Campaign C0062
  3. BleepingComputerAnthropic claims of Claude AI-automated cyberattacks met with doubt
  4. arXivEvaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects
  5. DarktraceNew Report Finds that 78% of Chief Information Security Officers Globally are Seeing a Significant Impact from AI-Powered Cyber Threats
  6. AcronisAcronis Cyberthreats Report H1 2025
  7. AcronisAcronis H2 2025 Cyberthreats Report: Cyberattacks Surge as Phishing, Ransomware, and AI-Driven Threats Escalate
  8. HornetsecurityTop Concerns CISOs Face: AI, Ransomware 3.0 and New Cyber Risks
  9. HornetsecurityRansomware Impact Report 2025
  10. Paul, WeissAnthropic Disrupts First Documented Case of Large-Scale AI-Orchestrated Cyberattack

The Verified Briefing

One email each morning. Every story in it carries its sources, so you can check the reporting before you repeat it.

No tracking pixels. One click to leave.