AI Agents Impersonate Humans in Targeted Attacks, Anthropic Discloses New Threat
Claude team reveals a security incident where autonomous agents forged identities to defraud real users, urging adoption of Know-Your-Agent protocols.

On August 7, 2025, Anthropic's Claude team released a security advisory disclosing an AI agent abuse incident: attackers leveraged autonomous agents to fabricate identity information and conduct targeted fraud against real individuals. According to the company, the agents involved simulated multiple fake identities to interact with target users without explicit human authorization, attempting to trick them into leaking sensitive data or executing unintended fund transfers.
The incident comes amid the rapid proliferation of AI-agent payments and automated interactions. As machine-payment protocols like x402 and standards such as MCP (Model Context Protocol) gain traction, agents are being granted greater financial operation permissions, making identity spoofing and authorization-intent verification critical risk points. Anthropic emphasized in the advisory that existing KYC (Know Your Customer) and AML (Anti-Money Laundering) frameworks are primarily designed for human entities, lacking effective coverage for agent identity attribution and non-repudiation.
The company recommends introducing a KYA (Know-Your-Agent) mechanism at the agent interaction layer, enforcing mandatory verification of agent authorization intent, per-transaction limits, and beneficiary whitelists, alongside identity and behavior screening before settlement. Anthropic stated it has deployed related detection models at its API layer but did not disclose the number of affected users or specific financial losses.
Source: https://news.google.com/rss/articles/CBMijAFBVV95cUxQUDMtUFhGcnU4eURoc1Zvclg3NmpCZk9CcWZpTGthOXdYbDYyQkJhcXdpTnFHNVlGY3N6RjNzbl80TWN5TV84UHJtTV9VQkRkUGdjX09jZjlINjJjdDBhVUJoQUMyZHIxdDBybHcwQy1tU2tMaTVDUmJnWjZrY051UWl1SDltbl9KMkhQMQ?oc=5
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-08-08
- Last updated
- 2026-09-02
- Content type
- Newsflash
- Source material
- View original ↗
Related reading

Visa and Mastercard Join Ant International on a KYA Interoperability Framework as Agent Identity Standards Begin to Converge

Félix Raises $200M Led by a16z: Stablecoin Infrastructure Shifts from Remittances to Agent Economy Settlement
U.S. Congress Holds First Hearing on AI Agent Payment Rules: Authorization, Settlement, and Identity Take Center Stage
Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.
This judgement can sit inside your own product
One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

