Beyond the now well-known criticisms surrounding high energy consumption and environmental impact, artificial intelligence is rapidly turning into a formidable threat to global cybersecurity.
Recent investigations have shown how virtual agents can transform into extremely powerful weapons even in the hands of those with no technical programming skills. An emblematic case, brought to light by researchers at OALABS, clearly illustrates this troubling trend.
AI Agents to Hack 14 Companies: The Profile of an Improvised Criminal

The attack was orchestrated by a young man from Ethiopia, who managed to compromise several servers and steal sensitive information from as many as 14 companies.
The attacker’s identity was discovered almost ironically: before launching the offensive, the young man asked Claude to correct and format his curriculum vitae, thereby giving the system his full name and geographic location. The conversation logs recovered by the owner of one of the breached servers show a completely inexperienced user.
His commands were formulated roughly, filled with grammatical errors and devoid of any technical jargon. Despite this evident inadequacy, the artificial intelligence generated all the code needed for the intrusion, enabling the young man not only to steal corporate data but also to attempt a cryptocurrency theft valued at approximately $4 million, an operation that fortunately failed.
The developing companies are aware of the risks. Anthropic, for example, has integrated safety filters to prevent its models, capable of detecting thousands of vulnerabilities in operating systems such as Windows and Linux, from being used for malicious purposes.
However, the attacker managed to bypass the defenses of Claude Opus with disarming ease. It was enough to claim to be part of a “red team”, i.e., a team of researchers authorized to test the cybersecurity defenses.
Misled by this premise, the system not only provided the code to hack the servers, but even suggested the most effective methods to monetize the operation, calculating the profits from extortion and the sale of the confidential data.
The only actual block by the virtual agent occurred when the young man attempted to target the digital accounts of a specific family, because the ethical protocols of security simulations never anticipate direct attacks on private individuals.
A Challenge for the Tech Industry
This episode demonstrates how easy it is to bypass current security systems. The software used by the Ethiopian hacker are consumer-grade versions, far less powerful than the variants reserved for large tech companies.
The speed at which these technologies evolve exposes infrastructures to enormous risks, because anyone can replicate similar attacks by delegating the entire technical part to machines.
Dramatically limiting the programming capabilities of these agents would penalize honest researchers who use them to strengthen corporate defenses, but maintaining the current level of accessibility makes it impossible to distinguish with certainty between requests from a security expert and those from a criminal intent on illicit profit.



