Claude AI lets Russian hackers hijack WhatsApp accounts of Ukraine officials

KI logo

Russian state-backed hackers have weaponized Anthropic’s Claude AI to strike Ukrainian and European targets, compromising government systems and hijacking WhatsApp accounts belonging to senior officials.

The revelation comes from a Sept. 10 threat intelligence report by Anthropic, the AI safety company behind Claude. It signals a dangerous escalation in how artificial intelligence reshapes state-sponsored cyber warfare. What once demanded expensive human expertise now happens faster, cheaper, and at greater scale.

The hacking group, which Anthropic tracks as GTG-20006, aligns with publicly known Russian threat actor Midnight Blizzard. One operator, a Russian speaker using the handle “JackPoterz,” demonstrated tradecraft consistent with Kremlin-linked espionage operations.

Targets spanned more than two dozen Ukrainian government bodies. Hackers probed email services and remote access infrastructure while focusing heavily on government ministries, military personnel, and diplomatic staff. Their reach extended into Europe, the Middle East, and maritime-related agencies in Asia.

Perhaps most striking: the group commandeered WhatsApp accounts through headless browser platforms, linking victim profiles as companion devices. They suppressed read receipts to avoid detection, then bulk-exported conversations in both Russian and Ukrainian. At least two former high-ranking Ukrainian officials fell victim to this method.

Anthropic’s investigation uncovered more than 20 distinct organizations in the actor’s operational planning and live attacks. Defense contractors, intelligence agencies, embassies, think tanks, and drone technology suppliers all appeared on the target list.

Meanwhile, the AI advantage proved decisive in evading security measures. Claude helped the group automate reconnaissance, identify which defenses had been bypassed, and autonomously modify malware to slip past existing detections.

The acceleration in attack speed remains the most concerning takeaway. Tasks that previously required significant manual effort from skilled hackers can now run on autopilot. That shift raises urgent questions about how defenders must adapt when adversaries deploy AI not as a novelty, but as standard operational infrastructure.