Anthropic finds AI automating more stages of cyberattacks
Anthropic reports that malicious actors are using AI to carry out and coordinate more stages of cyberattacks, from reconnaissance and exploitation to credential theft and data exfiltration.
Malicious actors are increasingly using AI to perform substantial parts of cyber operations, according to a September threat intelligence report from Anthropic. The report covers activity disrupted between December 2025 and August 2026 and includes suspected state-backed groups, financially motivated criminals, and politically motivated attackers.
Anthropic said most of the operations it examined involved AI directly executing or orchestrating attack steps. Humans generally remained responsible for selecting targets and reviewing results.
The report found that AI is being used to automate tasks that previously required teams of skilled operators, including scanning Internet-facing systems, developing exploits, processing stolen information, and managing multiple victims simultaneously. Some operations moved from initial access to extensive data theft within two or three hours. Anthropic cautioned that the cases examined were selected examples of notable or novel misuse and do not represent all malicious uses of AI.
One operation linked by Anthropic to reporting on the Russia-aligned Midnight Blizzard espionage group used AI-driven workflows for infrastructure acquisition, phishing, persistence, and data exfiltration. The system also monitored whether security products detected malware and automatically modified and rebuilt components when they were detected.
The report also identified DNS infrastructure as part of an attack involving at least three hospitality technology providers. Attackers altered DNS records to redirect hotel guest traffic through attacker-controlled services, which were then used to deliver malware and collect information about travellers. Ukrainian officials and people working in the drone industry were among the targets. Microsoft separately documented related activity in July under the name CaptiveCrunch and reported the manipulation of DNS and HTTP traffic on captive-portal networks in several countries.
AI credentials are also becoming targets. Anthropic described criminal groups collecting exposed API keys and session tokens from code repositories, mobile applications, containers, and customer environments. The credentials were then used as attack resources, sold, or used to conceal subsequent operations.
In one case, an attacker compromised an AI vendor’s evaluation environment, obtained production API keys, and used the access while probing around 30 AI companies over approximately four days. Anthropic said its own systems were not compromised.
The report also describes autonomous vulnerability-research workflows in which groups of AI agents operated in parallel and retained information between sessions. Anthropic concluded that the level of attacker sophistication is becoming a less reliable indication of the resources or state backing behind an operation as AI reduces the labour and expertise needed to conduct sustained cyber activity.
