Summary
- Anthropic says some observed attackers are using AI to execute and coordinate substantial parts of the intrusion lifecycle rather than simply answer technical questions.
- One Russia-linked operation targeted Ukrainian and European government, defence, diplomatic, and drone-technology organisations using AI-supported workflows.
- The cases suggest AI is changing the economics of existing cyber attacks by accelerating reconnaissance, adaptation, credential abuse, and exploitation.
Attackers using frontier artificial intelligence are beginning to automate substantial parts of cyber operations rather than merely asking a model how to write malicious code, according to new threat intelligence from Anthropic covering campaigns involving reconnaissance, phishing, exploitation, malware adaptation, and data theft.
The AI developer says it disrupted malicious activity using Claude between December 2025 and August 2026 across cyber operations, surveillance, influence activity, scams, weapons work, biological misuse, and attempts to extract capabilities from frontier models. Anthropic explicitly describes the cases as notable examples rather than a representative measure of ordinary activity across its services.
The strongest shift identified in the report is operational. Rather than using a model as an assistant for individual tasks, some actors built workflows in which AI systems conducted reconnaissance, generated or modified tooling, interacted with compromised environments, processed stolen information, and changed behaviour when defensive systems responded.
Humans still selected targets, supplied infrastructure, and reviewed outcomes, so the incidents do not amount to fully autonomous cyber attacks. The more immediate change is that one operator can delegate more of the technical workflow to software, increasing the amount of activity a relatively small team can sustain.
A Russia-linked espionage campaign provides the clearest European example in Anthropic’s report. The company says an actor it tracks as GTG-20006, whose behaviour it considers consistent with publicly reported Midnight Blizzard activity, used AI-driven workflows against government, diplomatic, defence, intelligence, and technology organisations concentrated in Ukraine and Europe.
Anthropic says those workflows supported infrastructure acquisition, phishing, command and control, persistence, exploitation, and data exfiltration. AI agents also monitored whether security tools were detecting malware and then modified and rebuilt the tooling when detections appeared, shortening the cycle between defensive response and attacker adaptation.
Drone technology featured prominently among the targets. According to the report, the actor obtained mailboxes from component manufacturers and stole a proprietary software development kit for a drone-vision system before analysing its architecture, hardware bill of materials, supplier dependencies, and information about an unannounced product.
Automation changes attack economics
Cyber operations have relied on automation for years, from internet-wide scanning and credential stuffing to scripted exploitation, which means AI does not introduce the idea of machine-assisted attacks. The change lies in how models can interpret unfamiliar systems and generate the next technical steps dynamically instead of depending on every variation being encoded in advance.
That flexibility can lower the amount of specialist labour required to maintain an operation. A capable model can process documentation, inspect stolen data, adapt scripts, analyse error messages, or suggest alternative techniques while a human operator concentrates on targets and strategic decisions.
For defenders, malware adaptation is especially awkward because detection traditionally imposes a cost on the attacker. Once a tool is identified, operators have to modify or replace it before continuing. An automated workflow capable of observing those detections and producing new variants can reduce that penalty even when defensive technology continues working as intended.
Anthropic also describes financially motivated actors using AI during credential theft, cloud compromise, software-supply-chain attacks, and data exfiltration. In one case, attackers moved from a stolen developer token to administrative control of a cloud environment within hours, demonstrating how identity compromise can provide a faster route than exploiting infrastructure directly.
Software suppliers remain particularly valuable targets because one compromise can create access to many downstream organisations. Anthropic documents operations in which breached service providers became routes into customer data, reinforcing a security problem that predates generative AI but becomes more attractive when attackers can automate reconnaissance and analysis across many victims.
Enterprise AI credentials are also becoming assets worth stealing. API keys and authenticated sessions can provide access to expensive model capacity while allowing malicious activity to be charged to a legitimate customer, and Anthropic says criminal groups are already brokering such access.
Model providers face a separate threat from large-scale attempts to extract capabilities through distillation, fake accounts, proxy networks, and stolen credentials. Whatever the competitive arguments around model access, frontier AI services now contain enough commercial and strategic value to attract systematic abuse resembling other high-value technology platforms.
There are limits to the conclusions that can be drawn from Anthropic’s evidence. The company sees activity on its own systems, the examples are selected because they are unusual, and threat attribution — particularly where state-linked actors are involved — remains probabilistic rather than absolute.
The report therefore does not establish how common AI-orchestrated attacks are across the wider internet, nor does it show models independently deciding to conduct operations. Human intent remains central throughout the cases described, even when software carries out significant parts of the technical work.
What changes is the relationship between attacker headcount and apparent sophistication. Rapid reconnaissance, polished tooling, large-scale data analysis, and repeated adaptation may no longer imply a comparably large human team if models can absorb much of the repetitive technical work.
That increases the value of controls that remain difficult to automate around. Strong identity security, narrowly scoped tokens, rapid credential revocation, segmentation, supplier oversight, secure API management, and limits on privileged access become more important when attackers can process more information and execute more tasks once an initial foothold is established.
AI is also being used defensively, and Anthropic says information from disrupted operations is feeding into stronger safeguards and threat sharing. The competitive effect therefore runs both ways: the same improvements that help defenders analyse software and incidents can help adversaries understand systems and adapt their methods.
The resulting change is less a new category of cyber attack than a different cost structure around existing ones. Phishing, credential theft, malware, cloud compromise, espionage, and supply-chain attacks remain familiar, but the amount of reconnaissance, adaptation, and execution one operator can coordinate is beginning to increase.












