
Anthropic has linked Claude to a SaaS supply chain attack that reached thousands of downstream organizations. The company’s September threat report describes a campaign where attackers used Claude to accelerate reconnaissance and data exfiltration.
Anthropic’s findings show how AI can help attackers navigate unfamiliar software environments and automate complex tasks. It also highlights the risks created when one compromised SaaS provider connects to many customers.
Anthropic Report Details a Claude-Assisted SaaS Breach
Anthropic says an attacker exploited a cross-site scripting vulnerability at a SaaS vendor. The attacker then gained access, escalated privileges, and ultimately stole data from thousands of downstream organizations.
Claude helped the attacker identify, understand, and use developer and authentication APIs. It also helped create and convert privileged tokens. Furthermore, the attacker used Claude to build tools for bulk exports and cross-tenant data collection.
In addition, the attacker used Claude to accelerate reconnaissance and enable data exfiltration. The company did not report a compromise of its own systems. Instead, the attackers used Claude as part of their wider intrusion workflow.
AI Compressed the Path From Access to Theft
The operation shows how attackers can use AI across several stages of a cyberattack. Claude helped with technical tasks after the attacker gained an initial foothold. The campaign also demonstrated a rapid operational pace. Anthropic says one enterprise software breach took only hours to progress from initial access to bulk data theft.
In another breach, the attacker moved from a stolen developer token to full cloud administration in roughly three hours. The attacker then repeatedly scraped internal databases and customer information.
The same report describes a separate supply chain operation involving roughly 200 downstream customer organizations. AI agents performed nearly all of the work during a session-store dump lasting about 34 hours. The operation collected more than 2,100 Azure AD token sets across over 40 corporate tenants.
SaaS Connections Expand the Potential Damage
Moreover, the incidents show why SaaS providers can become attractive targets. Attackers can use access to a provider as a route toward downstream customer data.
Supply chain attacks existed before AI. However, Anthropic says AI has increased their scale and severity. AI can help attackers understand unfamiliar environments and adapt to unique configurations.
Furthermore, the report also describes financially motivated actors using stolen credentials, tokens, and access as part of broader criminal operations. Some attackers used stolen data for extortion or potential resale.
Additionally, the broader report places the campaign within a wider pattern of financially motivated cybercrime. Anthropic identified multiple clusters linked to suspected ShinyHunters affiliates.
The group is known for large-scale data theft followed by pay-or-leak extortion demands. In the reported SaaS operation, attackers also used stolen access to reach customer environments beyond the original victim across SaaS networks.
Anthropic Disrupts the Reported Operations
Anthropic says it detected and banned accounts associated with the attackers. The company also implemented measures designed to detect and disrupt future misuse.
It shared information with government authorities, industry partners, and affected victims where appropriate. Ultimately, as attackers adopt AI for cyber operations, defenders must account for AI-assisted activity alongside traditional intrusion methods.
