Categorie: News

Inexperienced hacker used Claude and ChatGPT to hack 14 companies

Beyond the now well-known criticisms surrounding high energy consumption and environmental impact, artificial intelligence is rapidly turning into a formidable threat to global cybersecurity.

Recent investigations have shown how virtual agents can transform into extremely powerful weapons even in the hands of those with no technical programming skills. An emblematic case, brought to light by researchers at OALABS, clearly illustrates this troubling trend.

AI Agents to Hack 14 Companies: The Profile of an Improvised Criminal

Credits: Canva

The attack was orchestrated by a young man from Ethiopia, who managed to compromise several servers and steal sensitive information from as many as 14 companies.

The attacker’s identity was discovered almost ironically: before launching the offensive, the young man asked Claude to correct and format his curriculum vitae, thereby giving the system his full name and geographic location. The conversation logs recovered by the owner of one of the breached servers show a completely inexperienced user.

His commands were formulated roughly, filled with grammatical errors and devoid of any technical jargon. Despite this evident inadequacy, the artificial intelligence generated all the code needed for the intrusion, enabling the young man not only to steal corporate data but also to attempt a cryptocurrency theft valued at approximately $4 million, an operation that fortunately failed.

The developing companies are aware of the risks. Anthropic, for example, has integrated safety filters to prevent its models, capable of detecting thousands of vulnerabilities in operating systems such as Windows and Linux, from being used for malicious purposes.

However, the attacker managed to bypass the defenses of Claude Opus with disarming ease. It was enough to claim to be part of a “red team”, i.e., a team of researchers authorized to test the cybersecurity defenses.

Misled by this premise, the system not only provided the code to hack the servers, but even suggested the most effective methods to monetize the operation, calculating the profits from extortion and the sale of the confidential data.

The only actual block by the virtual agent occurred when the young man attempted to target the digital accounts of a specific family, because the ethical protocols of security simulations never anticipate direct attacks on private individuals.

A Challenge for the Tech Industry

This episode demonstrates how easy it is to bypass current security systems. The software used by the Ethiopian hacker are consumer-grade versions, far less powerful than the variants reserved for large tech companies.

The speed at which these technologies evolve exposes infrastructures to enormous risks, because anyone can replicate similar attacks by delegating the entire technical part to machines.

Dramatically limiting the programming capabilities of these agents would penalize honest researchers who use them to strengthen corporate defenses, but maintaining the current level of accessibility makes it impossible to distinguish with certainty between requests from a security expert and those from a criminal intent on illicit profit.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

The most invasive apps for privacy: Meta has five in the top 10, Instagram and Facebook leading

The weight of each data item depends on how it is processed. The most invasive…

10 hours ago

WhatsApp will remind you of your contacts’ birthdays

WhatsApp is getting ready to change, and in the latest beta versions new details about…

10 hours ago

Does Spotify take up too much space on your phone? A new feature could solve the problem

To make playback smoother and use less data when re-listening to a track, Spotify stores…

11 hours ago

iPhone 18 Pro and Pro Max Face ID issues: Apple prepares a fix

An attempted unlock withFace ID failed can be enough to crash the iPhone 18 Pro.…

12 hours ago

Galaxy Buds On: here are Samsung’s first clip-on earbuds

There should also be support for voice assistants, accessible directly from the earbuds. Samsung has…

12 hours ago

eBay: How Authenticity Verification Works, Now Available in Italy

Bags, sneakers and luxury watches sold on eBay can pass through the hands of an…

13 hours ago