{"id":77549,"date":"2026-06-17T22:02:14","date_gmt":"2026-06-17T22:02:14","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/77549\/"},"modified":"2026-06-17T22:02:14","modified_gmt":"2026-06-17T22:02:14","slug":"low-skilled-attacker-used-claude-codex-to-breach-14-companies","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/77549\/","title":{"rendered":"Low-skilled attacker used Claude, Codex to breach 14 companies"},"content":{"rendered":"<p>Researchers have long warned that <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/03\/23\/gidi-cohen-bonfy-ai-agent-security\/\" rel=\"nofollow noopener\" target=\"_blank\">AI agents<\/a> could lower the skill floor for offensive cyber operations, and a recent report by OALABS (Open Analysis) researchers bears that out.<\/p>\n<p>After recovering and analyzing over 1,000 agent sessions from a compromised server on which an attacker deployed Anthropic\u2019s Claude Code and OpenAI\u2019s Codex agents, the researchers discovered how easily the attacker was able to bypass most of the agents\u2019 guardrails, and how little he actually needed to know and do himself.<\/p>\n<p>\u201cIn many cases, the attacker supplied only vague, low-skill prompts and allowed Claude to fill in the gaps: researching exposed services, identifying possible vulnerabilities, writing exploit code, validating access, and harvesting data,\u201d the researchers noted.<\/p>\n<p>\u201cThe attacker did not need to be an expert operator; they simply had to use the correct framing for their prompts. The agent supplied much of the structure and technical execution that the attacker appeared to lack.\u201d <\/p>\n<p>A window into the attacks and the attacker<\/p>\n<p>The analyzed sessions were recoverable due to an operational security failure on the attacker\u2019s part, the researchers explained. <\/p>\n<p>Rather than running the AI agents on infrastructure he fully controlled, he copied them onto a server belonging to someone else. When that server\u2019s owner discovered the intrusion, they downloaded the attacker\u2019s entire working directory and shared it with the researchers.<\/p>\n<p>\u201cBecause the agents were local to the host, their full session logs were recovered, including the attacker\u2019s prompts, the tools used, the internal monologue of the large language model (LLM), and any policy violations recorded during the sessions,\u201d the researchers found.<\/p>\n<p>By analyzing the sessions, they discovered that:<\/p>\n<p>The Claude agent had been copied onto the host rather than installed, and that instance had previously belonged to a software developer.<br \/>\nThe attacker\u2019s working directory also contained other stolen Claude instances archived in 7-Zip folders, suggesting that hijacking and reusing other people\u2019s AI agent installations was the attacker\u2019s routine mode of operation.<br \/>\nThe attacker usually bypassed the agent\u2019s reluctance to execute hacking requests by claiming he was engaging in authorized red team exercises or cyber security research.<br \/>\nThe attacker used the agent to identify exploitable services on targets\u2019 systems, build custom exploits based on discovered vulnerabilities, execute these exploits against the targets, and exfiltrate data and credentials.<\/p>\n<p>The <a href=\"https:\/\/research.openanalysis.net\/claude\/codex\/hacking\/ai%20hacking\/llm\/redteam\/policy%20violation\/2026\/06\/16\/compromised-claude-hacking.html#Appendix-A---Post-Compromise-Timeline\" target=\"_blank\" rel=\"nofollow noopener\">prompt history<\/a> shows that almost all hacking activity was driven through the Claude agent, with the attacker preferring to issue vague directives such as \u201crecon this\u201d and allowing Claude to carry out the requests autonomously. <\/p>\n<p>\u201cFor each successful target, Claude would draft a \u2018PENTEST-REPORT\u2019 detailing how the access was gained and, more importantly, providing dollar-value \u2018monetization\u2019 estimates for the harvested data,\u201d they <a href=\"https:\/\/research.openanalysis.net\/claude\/codex\/hacking\/ai%20hacking\/llm\/redteam\/policy%20violation\/2026\/06\/16\/compromised-claude-hacking.html\" target=\"_blank\" rel=\"nofollow noopener\">shared<\/a>.<\/p>\n<p>\u201cBoth Claude and Codex raised the majority of their policy violation blocks during this phase, often correctly identifying that monetizing stolen data was likely not part of a legitimate redteam exercise. However, the attacker eventually obtained a list of suggested strategies, including extortion, access and data sale, business email compromise (BEC), and direct theft of funds.\u201d<\/p>\n<p>The collected sessions documented the breach of at least 14 companies, but there was no information in the logs to confirm that the attacker succeeded in monetizing the stolen data or stealing funds. <\/p>\n<p>The attacker\u2019s inexperience was also evident in his operational security failures. At one point he asked Claude to help edit his resume, which contained his full name, location, education history, and LinkedIn profile. <\/p>\n<p>Later, while investigating a potential compromise of one of his own hosts, he inadvertently confirmed his home IP address to the agent. Based on this and other corroborating evidence, the researchers believe the attacker to be a young man based in Addis Ababa, Ethiopia.<\/p>\n<p>The line between research and crime is hard to see (for AI)<\/p>\n<p>Across more than 1,000 sessions, Claude emitted only nine policy violations, and Codex only one, and in most cases, the attacker was able to work around them by reframing his request.<\/p>\n<p>The problem is that the framing that bypassed the guardrails here (\u201cauthorized red team engagements\u201d, \u201ccyber security research\u201d) is also the framing used by thousands of legitimate security professionals every day, and drawing a reliable line between the two may be an unsolvable problem.<\/p>\n<p>Blunting LLMs with broader refusals is not a good solution, the researchers feel, as it would hurt defenders more than attackers, who can simply turn to older or less restrictive non-frontier models.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/devider.webp\"\/><\/p>\n<p>Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. <a href=\"https:\/\/www.helpnetsecurity.com\/newsletter\/\" rel=\"nofollow noopener\" target=\"_blank\">Subscribe here!<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/devider.webp\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"Researchers have long warned that AI agents could lower the skill floor for offensive cyber operations, and a&hellip;\n","protected":false},"author":2,"featured_media":59049,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[179,53,3154,4174,42380,182,2798,313,2225,52],"class_list":["post-77549","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-agentic-ai","tag-anthropic","tag-anthropic-claude","tag-attack","tag-attack-tools","tag-claude","tag-claude-code","tag-cybersecurity","tag-llms","tag-research"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/77549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=77549"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/77549\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/59049"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=77549"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=77549"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=77549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}