As AI reduces the amount of expertise needed to conduct cyberattacks, it is widening the number of companies that might make tempting targets.
That’s one implication of a number of findings from Anthropic’s most recent Threat Intelligence report published earlier this month.
The report provided plenty of examples of the way powerful AI models are making cyberattacks almost trivially easy. In the past, the effort required to pull off a successful attack often meant that sophisticated hackers would choose to go after high-value targets. As the old saying goes, “why do robbers rob banks? Because that’s where the money is.”
But the rise of AI agents with genius-level cyber skills, all available at the push of a button, means that there is little cost in time and human effort to go after less obvious targets. Anthropic says this may mean many more companies will be attacked.
The company said it had found attackers using Claude to navigate corporate systems they barely understood, identify valuable data and write code to exploit vulnerabilities, the report said.
In one case, an attacker with a stolen developer token took full administrative control of a company’s cloud environment in roughly three hours, the report said.
A separate intrusion shows how far that work can carry an attacker. After breaching a software provider, attackers Anthropic described as suspected affiliates of “ShinyHunters” (which also recently claimed credit for a major data breach against the FBI) extracted data belonging to roughly 200 of its customers. Anthropic said AI agents performed nearly all the work.
The 154-page report covers activity Anthropic disrupted from December 2025 through August 2026. Alongside cyberattacks, it examines government surveillance, fraud, influence operations, weapons development, biological research, and unauthorized model distillation.
From stolen credentials to stolen data
During the software-provider intrusion, attackers extracted more than 2,100 sets of Azure AD authentication tokens across more than 40 corporate cloud environments, in about 34 hours. Such tokens can let attackers access cloud services as legitimate users without knowing their passwords.
The hackers supplied broad objectives and let Claude write and run scripts. If an approach failed, they instructed Claude to keep trying other tactics until one succeeded. Anthropic calls this “vibe hacking.” A way of running automated attacks that it described in a suspected state-backed campaign last November now appears across every type of cyber attacker it investigated. Attackers can download software that coordinates AI agents through different stages of an intrusion, the company said.
For example, a Russian-speaking attacker with a history of targeting hotel-booking and financial-technology platforms stole roughly 26 GB of data from one victim and sought $1.5 million to $2.5 million through extortion or dark-web sales, Anthropic said. The report describes the actor using parallel AI agents to investigate targets and test ways in. A later campaign from the same infrastructure targeted roughly 30 AI companies in about four days.
Meanwhile, in a campaign Anthropic linked to Russian espionage, agents monitored whether security products detected the operators’ malware. When malware was flagged, agents modified and rebuilt it in a workflow designed to keep iterating until it could successfully evade the security software.
Scammers are also supercharged
For scammers, AI has also become a vital tool to allow them to carry out highly targeted scams on a massive scale. A China-based app studio used Claude to operate more than 4,700 personas across a network of dating apps, conversing with at least 25,000 people over two weeks in April. Real gig workers handled tasks such as live video calls and social-media follows that helped persuade users the service was authentic. Users paid for messaging and matching through in-app coins.
This ability to catfish people at unprecedented scale also shows how con artists no longer have to be as selective in which victims they select, since there is minimal cost in running a highly individualized scam.
