IndiaFocal.

India, in focus.

National

Representative image · Photo: IndiaFocal
Representative image · Photo: IndiaFocal

AI Now Runs Parts of Cyberattacks Autonomously, Anthropic Report Finds

Anthropic's September 2026 report says threat actors used its Claude models to automate phishing, exploitation and data theft, prompting account bans and tighter safeguards.

Artificial intelligence is moving from a supporting tool to an active participant in cyberattacks, with threat actors using AI models to automate everything from phishing to data exfiltration, according to a new report from AI company Anthropic.

The report, Detecting and countering misuse of AI: September 2026, covers cyber operations that Anthropic identified and disrupted between December 2025 and August 2026, in which attackers used the company's Claude models. The actors involved ranged from suspected state-sponsored groups to financially motivated criminals and politically driven individuals.

Anthropic said the role of AI in these operations is becoming more autonomous. Claude was used not only as an assistant but also to execute or coordinate parts of attacks. In several instances, multi-agent AI systems handled reconnaissance, exploitation and data exfiltration, while humans largely confined themselves to choosing targets and reviewing stolen information.

One case involved a Russian state-nexus espionage actor identified as GTG-20006, which used AI-driven workflows to automate operations spanning infrastructure development, phishing, maintaining access to compromised systems and data theft. Its toolkit included Windows-based implants, a mobile exploitation kit, a credential-stealing tool targeting browser-stored passwords, and a phishing platform designed to imitate government organisations.

The group also leaned on AI to run its phishing operations, developing workflows to research and register domains, configure hosting infrastructure for phishing emails, send those emails and monitor command-and-control channels for successful compromises. More than 20 organisations featured in the group's planning, reconnaissance and live operations, including government ministries, defence and intelligence bodies, embassies, diplomatic missions, think tanks and defence-industrial companies.

The report also described financially motivated attacks in which Claude was used during large-scale data theft and supply-chain compromises. In one attack on a software-as-a-service provider, hackers extracted data belonging to around 200 downstream customer organisations and obtained more than 2,100 Azure AD token sets spanning over 40 corporate tenants in about 34 hours. AI agents performed nearly all of the work, according to the findings.

In another SaaS compromise, an attacker exploited a cross-site scripting vulnerability, escalated privileges and eventually exfiltrated data from thousands of downstream customer organisations. Claude helped the attacker understand developer and authentication APIs, create privileged tokens and build tools for bulk data exports and cross-tenant data collection.

Anthropic said its findings show AI is allowing attackers to operate faster and across more targets with fewer resources, increasingly taking over tasks that once required skilled human operators. The company warned that the risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources.

In response, Anthropic said it has banned accounts linked to the threat actors and strengthened its systems to identify similar attacks in the future. The company said it deployed additional monitoring to detect and ban related activity, is mapping the actors' wider footprints and tracking their digital signatures to prevent future misuse, and is incorporating the findings into new safeguards and model training.