Two Reports, One Conclusion
On September 10, 2026, Anthropic published its most detailed threat intelligence report to date: selected cases of Claude misuse that it detected and disrupted between December 2025 and August 2026. The cases span seven harm areas: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, scams and fraud, and illicit distillation.
Buried in the analysis is the sentence every defender should pin to the wall:
Two months earlier, on July 29, IBM and the Ponemon Institute had published the 2026 Cost of a Data Breach report, based on 602 organizations breached between March 2025 and February 2026. Read side by side, the two documents describe the same shift from opposite ends: Anthropic from the attacker's keyboard, IBM from the victim's invoice.
Who Is on the List
The actor list in Anthropic's report is the first thing worth reading slowly: suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, hacktivists, and politically motivated individuals.
Ten years ago, those categories lived in different leagues. State teams had budgets, custom tooling, and years of operator training. Criminal crews bought kits and rented infrastructure. Individuals mostly ran whatever someone else had built. In this report, they sit on the same page, abusing the same model, and in several cases running operations of comparable shape.
What "Closing the Gap" Looks Like in Practice
The report's cases show the gap closing along three different axes.
| Case (as described by Anthropic) | What AI did | What it replaced |
|---|---|---|
| Russia-linked espionage group | Automatically modified, rebuilt and redeployed malware whenever security tools detected it, against 20+ organizations | A malware development team |
| ShinyHunters-affiliated criminals | Mined credentials from a very large set of Android apps; one intrusion went from a single stolen developer token to full administrative control in roughly three hours | Weeks of manual recon and privilege escalation |
| China-based exploit research program | Ran unattended decompile-and-cross-reference loops against security products, on a schedule, targeting about 50 organizations | A vulnerability research lab |
| Commercial influence networks | Rewrote real articles into slanted versions for dozens of fabricated news sites and managed hundreds to about a thousand fake accounts | A content farm and its staff |
Anthropic uses the term "vibe hacking" for the pattern in the criminal case: the operator points the AI at a general goal and lets it execute the steps. Humans stayed in the loop for target selection, monetization and reviewing results. Everything in between, the part that used to require skill, was increasingly handled by the model.
We covered the espionage case in depth when it broke: Russian state hackers used Claude agents to rewrite their malware every time it got caught. And the same pattern showed up outside Anthropic's platform entirely, when one attacker ran hundreds of AI agents to breach 395 organizations through PaperCut.
AI Did Not Invent New Attacks. It Repriced the Old Ones.
Look at the table again and notice what is missing: a new technique. Malware that mutates to evade detection, credential harvesting, privilege escalation, reverse engineering, sock-puppet networks. Every one of them is decades old. What changed is the cost side of the attacker's calculation. Anthropic's report says it directly: AI autonomy compresses the cost of each campaign, lowering both the skill threshold and the labor required. When the price of a sophisticated operation drops by an order of magnitude, two things happen at once. Sophisticated attackers run more campaigns, and attackers who could never afford sophistication start running it. Defenders who built their threat model around "who would bother with us" have just lost their main assumption.
The Victim's Side of the Ledger
IBM's numbers describe what that repricing looks like once it lands.
- One in four malicious breaches was AI-enabled, a 56% increase over the previous year.
- An AI-enabled breach cost $6 million on average, against a record global average of $4.99 million for all breaches.
- The AI-enabled attacks were mostly deepfake impersonation and AI-enabled malware. Coverage of the report puts deepfakes and impersonation at 45% of AI-driven incidents, AI-enabled malware at 19%, and AI-generated phishing at 17%.
- More than 20% of organizations reported a breach that targeted their own AI models or applications, most often through compromised APIs, applications or plug-ins, or cloud misconfigurations affecting AI workloads.
The impersonation number deserves attention. The oldest control in business fraud prevention is "I recognized the voice." That control is gone. A cloned voice on a phone call or a synthetic face on a video call now costs the attacker minutes, and it is aimed straight at the person authorized to move money.
The Gap Did Not Close on Our Side
Attackers got a force multiplier. Many defenders did not. IBM reports that one in four organizations still has not adopted AI or automation in its security operations, while organizations that use it extensively cut breach costs by almost $2 million. Coverage of the report also describes shadow AI, meaning tools employees use without approval, in 43% of breached organizations, and finds that the large majority of organizations hit by an AI-related breach had no proper AI access controls in place. In other words, the same technology that lowered the attacker's skill threshold is also widening the defender's attack surface, and most of it is not inventoried, let alone governed.
Who Gets Hit Hardest
For years, small organizations relied on an unwritten argument: "We are too small to be a target. Advanced attacks are for banks and governments." It was never entirely true, but it held because sophistication was expensive and attackers spent it where the payoff was largest.
That argument is finished. When a single operator can run a campaign that used to take a team, the long tail of targets becomes profitable. The organizations most exposed are the ones with the thinnest defense budget relative to their digital footprint:
- Small and mid-sized businesses, especially those without a dedicated security person.
- Local governments, schools and hospitals, which hold valuable data on legacy systems.
- Fast-digitizing emerging markets, such as West Africa, where mobile money, digital banking and e-government services are growing faster than the security teams that protect them. Impersonation and account takeover map directly onto mobile money fraud, and AI makes those attacks cheaper to run in any language.
What I Would Put in Place Tomorrow
None of this requires a Fortune 500 budget. It requires moving the baseline to where the attackers already are. This is the order I would work in.
1. Phishing-Resistant MFA on Everything That Matters
AI-written phishing has no typos, no odd grammar, and is personalized from public data. Training people to spot bad emails is losing its value. Passkeys and FIDO2 hardware keys make a stolen password, and even a real-time phished one-time code, useless. Start with email, identity provider, VPN, finance and admin accounts.
2. A Call-Back Rule for Money and Credentials
Any request to move money, change bank details, reset MFA or share credentials gets verified through a separate, pre-registered channel, no matter how convincing the voice or the video looks. Write it down, make it non-negotiable, and make sure executives follow it too, because they are the ones being impersonated.
3. Segment the Network So One Laptop Is Not the Company
In the ShinyHunters case, one developer token became full administrative control in about three hours. Segmentation, least-privilege service accounts and separate admin accounts turn that three hours back into three weeks, which is long enough for someone to notice.
4. EDR and Centralized Logging, Even for Small Teams
Malware that rewrites itself to evade signatures is exactly what signature-only antivirus cannot catch. Behavior-based endpoint detection plus centralized logs, even a lightweight setup, gives you a chance to see the pattern instead of the file. If you cannot staff it, use a managed detection service.
5. Inventory Every AI Tool and Agent
You cannot protect what you cannot see. List every AI tool, browser extension, plug-in and agent in use, who approved it, what data it touches, and what credentials it holds. Then give agents their own identities with scoped, revocable permissions instead of borrowing a human's.
6. Use AI on Defense
The organizations saving almost $2 million per breach are the ones using AI and automation in security operations: triage, correlation, phishing analysis, vulnerability prioritization. The attacker already has a force multiplier. The defender needs one too.
The baseline has moved. Controls that used to be "nice to have for mature companies" are now the minimum for anyone connected to the internet. Your attacker is no longer selected by your size. It is selected by your exposure.
Frequently Asked Questions
My Take
Most of what I have written this month has been about AI agents misbehaving inside the labs: Gemini logging into real companies during a test, OpenAI agents using a dead wiki as a message board. This story is the other half of the picture, and in practical terms it matters more. These are not models going off-script. These are people using models exactly as intended, for the wrong reasons.
The honest summary is simple. AI did not invent new attacks. It made existing attacks cheap, fast and available to anyone with a goal and an account. The skill that used to protect us by being scarce is no longer scarce.
The good news is that the defense playbook is not a mystery. Phishing-resistant MFA, a verification rule for money, segmentation, behavior-based detection, an inventory of your AI, and AI on your own side. None of it is new. What is new is that it is no longer optional, whatever your size and wherever you operate.
So the question for every security team, and every business owner without one, is uncomfortable but useful: are you still defending like it is 2023?
Related Articles:
- Russian State Hackers Used Claude Agents to Rewrite Their Malware Every Time It Got Caught
- One Attacker, Hundreds of AI Agents: How a Swarm Breached 395 Organizations Through PaperCut
- Gemini Thought It Was Still in the Test. It Was Logging Into Three Real Companies.
- Frontier AI Agents Built Their Own Attack Chains. Nobody Told Them To.
- OpenAI Rated Its Own Model "Critical" for Cyber. Google and Anthropic Moved the Same Week.
- Zero Trust Security with AI: A Network Engineer's Guide