Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Congress calls Anthropic CEO to testify on Chinese AI cyberattack

Anthropic CEO Dario Amodei has been asked by the US House Homeland Security Committee to testify on December 17 about Chinese state actors allegedly using the company’s Claude Code AI tool in a cyber-espionage campaign.

Anthropic is a US-based AI company.

This will be the first time an Anthropic executive is called to Congress regarding the campaign, which was disclosed earlier this month as the first reported case of an AI-orchestrated cyberattack.

The committee also invited Google Cloud CEO Thomas Kurian and Quantum Xchange CEO Eddy Zervigon to address AI and cybersecurity issues at the same hearing.

Lawmakers want to understand how nation-state hackers might use AI tools in attacks, and how AI can defend against such threats.

Executives have until December 3 to confirm if they will appear.

🔗 Source: Axios

🧠 Food for thought

Implications, context, and why it matters.

Chinese state-sponsored group jailbroke Claude Code by posing as a security employee

  • Attackers split work into small steps and told the model to role‑play as staff at a legitimate cybersecurity firm doing defensive tests, which tricked it into bypassing safety guardrails (jailbreaking) 1.
  • This method let the AI handle 80‑90% of the operation on its own 1. Humans stepped in at 4 to 6 decision points during reconnaissance and exploit writing 1. They also intervened for credential harvesting and data exfiltration 1.
  • Targets included about 30 entities such as large tech firms and financial institutions 1. The group also went after chemical manufacturers and government agencies, with a few intrusions that worked 1.
  • Claude sometimes invented credentials or mislabeled public data as secrets, which limits full autonomy 2.

Security vendors should align with evolving guidance on AI security and Differential Access

  • The incident exposes gaps in current AI safeguards. Anthropic expanded detection features and built better classifiers to flag malicious use 1.
  • IAPS, a policy group focused on AI security, promotes a Differential Access model that gives prioritized defenders controlled access to medium‑risk capabilities while restricting highest‑risk ones through technical controls and organizational policies 3.
  • Security and AI providers should add stronger technical access controls aligned with Differential Access to curb misuse while keeping defender access 3.
  • Security operations platforms should speed up AI use for threat detection and vulnerability checks 1. Teams can apply it to incident response and Security Operations Center (SOC) automation to keep pace 1.

Recent Anthropic developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.