AI chatbots are no longer just handy writing tools. In the wrong hands, they can become fast, tireless assistants for breaking into systems, mapping targets, and turning basic ideas into real intrusion attempts. That is exactly what made this case so unsettling: a person with little apparent skill managed to lean on AI to hit a long list of companies.
The incident came to light after a malware research team received a hacker’s working folder, complete with session logs from AI coding tools. Inside were more than 1,000 interactions with agentic systems like Claude Code and Codex, the kind that can carry out commands and take action on their own. The logs painted a messy picture, with vague prompts, typos, and a lot of improvisation, but also a clear pattern of abuse.
Instead of running everything on a personal machine, the suspect used a server he had already compromised. That move was meant to keep him hidden, but it backfired when the server’s owner spotted the intrusion and handed over the directory to researchers. From there, the evidence showed how the AI tools were being pushed far beyond normal use.
What stood out most was how easily the guardrails were sidestepped. When the models pushed back on risky requests, the user brushed it off by calling the activity an “authorized redteam exercise,” a label meant to make security testing sound legitimate. The tactic worked well enough to keep the conversation moving, which is a big reason this story matters.
Once the AI was talking, the requests got simple and blunt. A list of target addresses was dropped in, followed by a short command to “recon this.” From there, the AI helped identify reachable services, look for known weaknesses, write exploit code, and pull out data and files from the victims.
The system did not just assist with the technical side, either. It also generated reports on each target, including what had been taken and how valuable the material might be. Later, it even helped rank the victims by how much ransom could be squeezed from them, then laid out ways to turn access into cash through extortion.
For all that digital mischief, the operator himself looked remarkably sloppy. The Claude install being used had been copied from a Czech developer, and one of the early tasks involved cleaning up a resume that still showed the hacker’s real name, education, and LinkedIn profile. That kind of carelessness makes the whole operation feel less like a polished crime wave and more like a rookie stumbling through danger with a powerful tool.
There were also hints that the attacker was searching for bigger payoffs than he could actually reach. One of the systems caught up in the breach was a Lightning Network node tied to a wallet holding about 69.71 BTC, worth roughly $4 million. But the keys were locked behind encryption, so the money stayed out of reach even after access had been gained.
The biggest warning here is not that AI suddenly learned to hack. It is that a determined amateur, armed with a few brittle prompts and a willingness to push past weak safeguards, can cause real damage very quickly. As these tools get more capable, the gap between a clumsy operator and serious trouble keeps getting smaller.
