Hackers used Anthropic's Claude AI model to conduct intrusions into OpenAI, the Wall Street Journal reported, in what appears to be one of the most high-profile cases of AI being weaponized against a major technology company. The report adds serious weight to concerns that large language models are becoming standard tools in the arsenal of sophisticated threat actors.
What the Attack Involved
Details from the WSJ report indicate the attackers used Claude to assist in planning and executing the breach, though the full scope of what was accessed inside OpenAI's systems has not been publicly confirmed. The two companies are direct competitors in the AI industry, which makes the incident particularly sensitive. Both have significant security teams and handle vast amounts of proprietary research and user data. This is not an isolated incident. Hackers previously used Claude to breach nine Mexican government agencies, a case that demonstrated how AI assistance can scale intrusion campaigns across multiple targets rapidly.
Key Facts
- Wall Street Journal reported the breach in an exclusive investigation
- Anthropic's Claude was used as an attack tool against OpenAI's systems
- The incident follows a documented pattern of threat actors misusing AI models
- Both companies are competitors in the generative AI market
- Anthropic has previously acknowledged misuse cases involving Claude
Anthropic has been candid in recent months about attempts to misuse Claude for malicious purposes. The company has published threat research identifying state-linked groups as among those probing its systems for offensive use cases. Russian SVR hackers were found to have used Claude AI in cyber strikes, an incident that forced Anthropic to take a harder look at how its models are being accessed and exploited. The OpenAI breach, if confirmed in full detail, would represent an escalation in both the profile of the target and the competitive dimension of the attack.
The use of AI models in offensive cyber operations is no longer theoretical. These are active, documented campaigns using commercially available tools against high-value targets.Cybersecurity analyst commentary on AI-assisted intrusions
A Broader Pattern Emerges
The WSJ report lands against a backdrop of increasing scrutiny over how AI companies manage the dual-use risks of their own products. Iran used Claude to target US Navy assets in the Middle East, according to Anthropic's own disclosures, suggesting that state-sponsored actors view frontier AI models as legitimate components of their operational toolkit. Security researchers have long warned that the same capabilities that make models like Claude useful for legitimate tasks, such as summarizing complex information, writing code, and planning multi-step workflows, also make them useful for reconnaissance and attack planning.
For Anthropic, the report presents a reputational and policy challenge. The company has positioned itself as a safety-focused AI developer, and Claude's use in breaching a direct competitor in the AI space will likely draw scrutiny from regulators and the broader tech industry. Anthropic has previously cooperated with law enforcement and published transparency reports on misuse, but questions will now center on whether existing safeguards are sufficient to prevent Claude from being used in high-profile corporate espionage.
OpenAI has faced security incidents before. In 2023, reports emerged that an attacker had accessed internal company communications, though that breach did not reach core systems. A Claude-assisted attack, if substantiated in full, would represent a qualitatively different threat, one where AI accelerates the attacker's capabilities in ways that traditional security tools may not anticipate.
The incident is likely to surface at upcoming policy forums where AI governance is on the agenda. Both Anthropic and OpenAI have executives engaged in international regulatory discussions, and a high-profile breach of this nature could shift the conversation toward mandatory incident reporting and stricter access controls for frontier models. The full picture of what was taken and how far the intrusion reached inside OpenAI may take weeks to emerge publicly, but the early reporting suggests this is a story that will have consequences well beyond the two companies involved.