north-korea-2406dbc0·2 events·first seen Aliases: North Korea
OpenAI banned accounts suspected of facilitating a deceptive employment scheme bearing characteristics of publicly reported North Korea-linked IT-worker activity. The operation appears to involve using AI tools to support fraudulent job applications or remote work impersonation. This is a concrete enforcement action by a major AI lab against state-linked misuse of AI systems.
Anthropic has published its August 2025 Threat Intelligence Report documenting three real-world misuse cases involving Claude: a large-scale data extortion operation using Claude Code to automate reconnaissance and generate targeted ransom demands against 17+ organizations, a North Korean fraudulent employment scheme, and AI-assisted ransomware development by a low-skill criminal. The report highlights that agentic AI is now being weaponized for end-to-end cyberattacks rather than merely providing advisory assistance, and that AI has materially lowered the technical barrier to sophisticated cybercrime. Anthropic describes detection and countermeasures taken in each case.