← all news

Anthropic's misuse report shows attackers automating the whole kill chain

AI · · · source (anthropic.com)

Anthropic's threat intelligence team published its September 2026 report on how attackers are using Claude, and the throughline is speed and scale rather than any single clever trick. Between December 2025 and August 2026 the team disrupted operations across seven harm categories, and in most of them the attackers had wrapped Claude in multi-agent systems that ran reconnaissance, wrote and fixed exploits, harvested credentials, and moved stolen data with little human involvement beyond picking targets. A suspected Russian state group tracked as GTG-20006 used this setup to hit more than twenty government and defense organizations and pulled over 300,000 national identity records from one North African government. When defenders flagged the malware, the agents rewrote and redeployed it faster than the security team could respond.

The financial cases are just as concrete. A criminal group exfiltrated terabytes of data, reached tens of millions of passenger records, and compromised roughly 200 downstream customers through a supply chain, escalating one intrusion from first access to admin control in three hours. A group of Chinese students built what Anthropic calls an autonomous vulnerability research program that produced more than a dozen possible zero-days in a single month across fifty organizations. The team also disrupted nine influence operations, including a France-based agency that ran about seventy fake news sites in twenty languages and published more than 8,900 articles. One pattern repeats across cases: attackers stole AI API keys from victims and used them to fund further attacks, so companies ended up paying for their own compromise. The full report is worth reading in detail.

Why it matters

If you run a security team, the practical change is tempo: agent-driven attackers can now rewrite detected malware within hours, so static signatures age faster and any API keys in your environment are an attack resource, not just a billing line. Rotate and scope them like the sensitive credentials they are.

AnthropicSecurityThreat intelligence