AI Is Lowering the Bar for Sophisticated Cyberattacks, Report Finds
A new report says AI is letting lone hackers automate complex cyberattacks, with state-linked groups and criminals using Claude across the attack chain.
Artificial intelligence is eroding the technical barriers that once separated skilled cybercriminals from opportunists, according to a report by Anthropic, which warns that sophisticated attacks no longer demand sophisticated attackers.
The report, titled Detecting and countering misuse of AI: September 2026, says AI use has moved past simple chatbot exchanges into multi-agent systems that can handle reconnaissance, exploitation and data exfiltration. Over a six-month period, the company's Threat Intelligence team identified and disrupted a series of cyber operations in which threat actors used its Claude model.
Those actors included suspected state-sponsored groups, financially motivated criminals and politically motivated hacktivists, the report says, with some running campaigns against multiple victims at once.
According to the findings, AI has boosted offensive capabilities across the entire attack chain — from reconnaissance and tool development to data processing and exploitation.
One case highlighted in the report, identified as GTG-20006, illustrates how automation is reshaping attacks. The actor deployed a custom toolkit featuring Windows-based implants, a mobile exploitation kit, a credential-stealing tool aimed at browser password stores, a phishing platform mimicking government organisations and an administrative console for managing compromised accounts.
AI-assisted workflows allowed the group to rebuild and redeploy its toolkit automatically whenever security products detected it, and to monitor how well its tools evaded known defences. The actor also leaned on AI to identify targets, build phishing infrastructure, execute intrusions, steal credentials and move laterally across victim networks, as well as to extract and organise hundreds of gigabytes of stolen data and sustain access to compromised systems.
The investigation found more than 20 distinct organisations in the actor's planning, reconnaissance and live operations. They included government ministries, defence and intelligence bodies, embassies and diplomatic missions, think tanks and defence-industrial companies, concentrated in Ukraine and Europe but extending to the Middle East and maritime-related government agencies in Asia.