WorkAugust 25, 2026via The Decoder
Taiwanese cybersecurity firm warns that AI tools have more than doubled Chinese state-backed cyberattacks
Why it matters
AI capability democratization is reshaping cybersecurity threat vectors. Practitioners need to understand how frontier models (open and closed) are accelerating state-actor attack velocity and sophistication, forcing defensive posture changes.
Key signals
- Chinese state-backed cyberattacks more than doubled since AI adoption
- Attackers using DeepSeek, ChatGPT, and Claude Code for exploit generation and network scanning
- UK study confirms open models' cyber capabilities approaching parity with frontier models
- Source: TeamT5 (Taiwanese cybersecurity firm)
- Threat actor: Chinese state-backed hacking groups
The hook
Chinese state-backed hacking groups more than doubled attacks using AI models like DeepSeek and Claude to write exploit code—a real-world consequence of open AI capabilities.
Chinese state-backed hacking groups have more than doubled their attacks since they started using AI models like DeepSeek to write exploit code and scan networks, according to Taiwanese security firm TeamT5. Hackers also used ChatGPT and Anthropic's Claude Code. A UK study shows the cyber capabiliti…