Anthropic has reported a significant evolution in cyberattacks involving AI. Between December 2025 and August 2026, threat actors used Claude to automate and coordinate multiple stages of real-world attacks, including reconnaissance, phishing, exploitation, credential theft, lateral movement and data exfiltration.
The concern is not simply that attackers are using AI to write malicious code, rather AI has increasingly been used as an operational assistant, allowing attackers to automate technical tasks, analyse stolen information and adapt their activity with limited human intervention.
What Happened
One notable campaign, attributed to GTG-20006, involved activity consistent with the Russian state-linked group Midnight Blizzard (APT29). More than 20 organisations were targeted, including government, defence, diplomatic and intelligence-related organisations.
The attack chain included:
Reconnaissance → Phishing → Credential Theft → Persistence/Lateral Movement → Data Collection → Exfiltration
Claude assisted with identifying targets, building phishing infrastructure, stealing credentials, modifying malware when detected and processing large volumes of stolen data.
Another campaign linked to ShinyHunters used Claude to scan approximately 1.8 million Android applications for exposed secrets such as API keys and credentials. The attackers then used the discovered credentials to support further intrusions and data theft.
In a separate operation, attackers compromised a SaaS provider and used that access to reach approximately 200 downstream customer organisations, demonstrating how AI-assisted attacks can amplify supply-chain risk.
Why It Matters
AI is lowering the technical barrier to sophisticated attacks while increasing their speed, scale and adaptability.
Previously, an operation involving reconnaissance, exploitation, malware development and data analysis would typically require several skilled operators. AI can now assist with many of these activities in a single workflow.
For defenders, this means traditional controls focused only on known malware may be insufficient. Organisations should pay greater attention to behavioural indicators, such as unusual authentication, bulk data access, unexpected token creation, mass API activity and rapid movement between systems.
The threat is particularly relevant to organisations with large cloud environments, SaaS dependencies, privileged accounts and valuable customer data.
Recommendations
- Strengthen monitoring for phishing-resistant MFA bypass, unusual sign-ins, device-code authentication and suspicious token activity.
- Monitor for exposed credentials, API keys and tokens, and track relevant threat actors targeting cloud/SaaS environments.
- Enforce least privilege, secrets scanning and stronger controls around privileged tokens and AI applications.
- Conduct controlled assessments of identity, cloud and AI environments to identify credential exposure, privilege escalation and excessive access.
- Correlate reconnaissance, credential access, privilege escalation, collection and exfiltration activity to improve detection beyond malware-based alerts.




.jpeg)

.png)

.png)
.png)