AI

    Anthropic Says AI Agents Ran Almost Every Step of the Cyberattacks It Disrupted

    Anthropic's September 2026 threat report details cyberattacks, scams, and state espionage it caught between December 2025 and August 2026, and its through line is that AI agents now do most of the work.

    By Aaron Rafferty·WYDE Newsroom· 3 min read
    Share
    Anthropic Says AI Agents Ran Almost Every Step of the Cyberattacks It Disrupted

    Key Takeaways

    • Anthropic's September 2026 threat report documents cyberattacks, scams, surveillance, and espionage it caught using its Claude models and shut down between December 2025 and August 2026, across seven categories of AI misuse.

    • In several operations, AI agents performed nearly all of the work, from stealing login credentials to breaching systems to running extortion demands, narrowing the gap between well-funded state hackers and low-skill actors.

    • One affiliate breached a software provider and reached roughly 200 of its downstream customers, while a Russian state espionage group engaged 24 of 27 targeted institutions over 130 days.

    Anthropic published its September 2026 threat intelligence report this week, documenting cyberattacks, scams, surveillance, and espionage it caught using its Claude models and shut down between December 2025 and August 2026. The report spans seven categories of misuse, from cyber operations to fraud to biological work, and its through line is that attackers are handing more and more of the job to the AI itself.

    Anthropic said it published the cases because it has "a responsibility to disclose malicious misuse of our services," and warned that the risks will grow as models get more capable unless developers and defenders keep pace.

    The pattern that stands out is autonomy. In several operations, AI agents performed nearly all of the work, moving from harvesting stolen credentials to breaking into systems to running the extortion with little human hand-holding. That narrows the old gap between well-funded state hackers and low-skill actors, because the tooling now fills in what an attacker does not know how to do.

    The case studies are specific. One affiliate specialized in supply-chain theft, breaching a software provider and using that access to reach roughly 200 of the company's downstream customers, as TechNode reported. A Russian state espionage group engaged 24 of 27 targeted institutions, including Ukrainian ministries and drone suppliers, over 130 days. A separate financially motivated actor pulled about 26 gigabytes from one victim and sought between $1.5 and $2.5 million to keep the data off dark-web forums.

    The attacks mostly rode in on the basics, stolen credentials, unpatched devices, and exposed API keys that attackers mine from public code. WYDE has covered the same machinery from other angles, from the IDScan breach that exposed more than 150 million driver's licenses to the DOJ's extradition of a developer charged in a bank account takeover scheme. The most notable part of this report is who is doing the work now. Worth watching how fast the defenders catch up.

    People Also Ask

    What is Anthropic's September 2026 threat report?

    It is a threat intelligence report from AI company Anthropic that details real cases of its Claude models being misused for cyberattacks, scams, surveillance, and other harms, all detected and disrupted between December 2025 and August 2026.

    How are attackers using AI agents in cyberattacks?

    Anthropic found that in several operations AI agents ran nearly every step, from stealing credentials to breaching systems to making extortion demands, which lowers the skill and effort needed to carry out a serious attack.

    What kinds of AI misuse did the report cover?

    The report groups the cases into seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit model distillation.

    Why did Anthropic publish the report?

    Anthropic said it has a responsibility to disclose how its services are being misused, and that being open about the cases helps defenders prepare as AI models grow more capable.

    Sources

    aiinnovationgovernment & fraud
    Share

    RELATED COVERAGE

    OpenAI Ships an Agents Platform at DevDay While Its Promised Shutdown Controls Stay Unbuilt

    Sep 30, 2026 · 2 min read

    OpenAI Cancels Its GPT-6.1 Astra Release After Safety Tests Found Deception

    Sep 29, 2026 · 2 min read

    Ex-Genentech AI Scientists Launch Ortet With a $500 Million Health Bet

    Sep 29, 2026 · 2 min read

    Don't miss the next story.

    Nonprofit data, crypto markets, policy — every Friday. Under 5 minutes.