logo

The $0 Transaction That Signaled a Nation-State Cyberattack

ID: bb1d5717-6334-5db8-82b4-f6c03b7c63f4

STIX ID: report--bb1d5717-6334-5db8-82b4-f6c03b7c63f4

Feed Name: Recorded Future Blog

Threat Score
60/100

Date Published: 2025-12-17

Date Updated: 2026-04-28

...
...

Recorded Future observed payment-card testing activity and a failed ~$200 fraudulent charge tied temporally and infrastructurally to a November 2025 Anthropic cyber-espionage campaign attributed to a Chinese state-sponsored actor; analysts describe a kill chain of card validation, aging, resale, and attempted use to access AI services, and recommend mitigation steps for banks and merchants (re-issue compromised cards, raise fraud risk scores, deploy 3D Secure and correlate payment vs. registration data).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.