Connect with us

Hi, what are you looking for?

AI Cybersecurity

Factory Disrupts State-Linked Cyberattack Using AI to Hijack Development Platform

Factory thwarts a state-linked cyberattack using AI-driven tactics to hijack its software platform, revealing a major threat to global cybersecurity resilience.

Factory, a San Francisco-based startup, recently thwarted an attack from a state-linked threat group that aimed to hijack its software development platform as part of a global cyberfraud operation. The company identified the attackers, some of whom are believed to be associated with state actors from China, who employed AI-driven coding agents to adapt their strategies in real time against Factory’s cyber defenses.

The primary intent behind this breach appeared to be the aggregation of various AI products, enabling the attackers to resell access as part of a broader cybercrime operation. According to Factory’s Chief Technology Officer, Eno Reyes, the assailants aimed to exploit free-tier access and onboarding pathways across multiple AI providers, including Factory, to create a large-scale fraudulent network. Reyes stated, “Their objective was to repurpose AI platforms like ours as compute and tooling nodes within a broader mesh of ‘off-label’ model usage.”

The attack, first detected on October 11, lasted for several days, during which Factory examined its logs and noticed unusual patterns of thousands of organizations using its Droid product. The analysis revealed that this activity deviated significantly from the typical usage patterns expected from legitimate customers.

During the investigation, Factory uncovered multiple Telegram channels promoting free or discounted access to premium AI coding assistants. Additionally, these threat actors were found to be offering access to vulnerability research on third-party targets alongside various cybercrime resources.

This incident coincided with recent disclosures from Anthropic regarding a sophisticated espionage campaign primarily leveraging AI infrastructure. James Plouffe, a principal analyst at Forrester, noted that the attacks on Factory and Anthropic could demonstrate a viable proof of concept for AI-driven attack infrastructure. Plouffe explained that the attacks allow adversaries to “probe the detection and response capabilities of the frontier AI companies themselves.”

Factory has shared its findings with relevant security agencies and regulatory authorities, highlighting the urgent need for enhanced cybersecurity protocols as AI technologies become increasingly integrated into various sectors.

This incident raises significant questions about the resilience of AI platforms against sophisticated cyber threats. As AI becomes more ubiquitous, the risk of exploitation by malicious entities grows. The need for robust cybersecurity measures is paramount, especially as organizations increasingly leverage AI technologies for critical operations.

Moving forward, it is essential for AI companies to not only enhance their security provisions but also to establish protocols for collaborative information sharing among industry peers. This can bolster collective defense mechanisms against such advanced threats. The evolving landscape of cybercrime necessitates a proactive approach to security, particularly in the context of AI-driven technologies.

In conclusion, the attack on Factory by state-linked threat groups underscores the importance of vigilance in the AI sector. As the technology continues to evolve, so too must the strategies to defend against those who seek to exploit it for nefarious purposes.

See also
Rachel Torres
Written By

At AIPressa, my work focuses on exploring the paradox of AI in cybersecurity: it's both our best defense and our greatest threat. I've closely followed how AI systems detect vulnerabilities in milliseconds while attackers simultaneously use them to create increasingly sophisticated malware. My approach: explaining technical complexities in an accessible way without losing the urgency of the topic. When I'm not researching the latest AI-driven threats, I'm probably testing security tools or reading about the next attack vector keeping CISOs awake at night.

You May Also Like

AI Government

Anthropic accuses Moonshot AI of 3.4M unauthorized exchanges with its Claude chatbot, prompting a global U.S. State Department campaign against IP theft.

AI Regulation

US designates Anthropic as a supply chain risk, prohibiting federal use of its AI, while the NSA actively employs its Mythos model for cybersecurity.

Top Stories

Cambricon surges to $423M in Q1 revenue with a 160% increase, outpacing Nvidia's dwindling market share in China, now below 60%.

AI Generative

SenseTime unveils SenseNova U1, an open-source model that processes images directly and faster than competitors, aiming to reclaim its position in AI innovation.

AI Tools

China penalizes three online platforms for failing to label AI-generated content, intensifying efforts to combat misinformation as generative AI activities soar to 602 million...

AI Business

Initta Technology unveiled its AI-driven "Infinity" pavilion at CHINASHOP 2026, attracting over 70,000 attendees and showcasing its groundbreaking Trio solution suite for smart retail...

AI Generative

DeepSeek unveils V4 AI model with advanced reasoning and agentic capabilities, outperforming OpenAI's GPT-5.2 while integrating Huawei chips for enhanced autonomy.

AI Business

Amazon Web Services launches AI-driven tools for logistics and recruitment, aiming to capture a share of the $300 billion SaaS market.

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.