AI Agents Are Powering Real Cyberattacks|Midjourney AI News
Anthropic says threat actors used Claude to accelerate real cyberattacks, including a cloud takeover completed in roughly three hours.
Source: https://www.anthropic.com/threat-intelligence-report-september-2026?page=1

AI agents are no longer just a productivity tool for developers and businesses. Anthropic says threat actors are using AI agents to accelerate real-world cyberattacks, allowing attackers to move faster across reconnaissance, privilege escalation and data theft.
In its September 2026 threat-intelligence report, Anthropic described several cases in which criminals and other threat actors used Claude during cyber operations. The company said it identified and disrupted the associated activity and used the findings to strengthen its safeguards.
One of the most striking cases involved a software company where attackers went from a single stolen developer token to full administrative control of the victim's cloud environment in roughly three hours. After gaining access, the attackers used AI-assisted workflows to explore internal systems and extract data.
Anthropic also described a separate supply-chain attack involving a software-as-a-service provider. The attackers used Claude to understand developer and authentication APIs, create tools, work with privileged tokens and automate large-scale data collection across downstream customer environments. In one case, AI agents performed nearly all of the operational work during the data-collection process.
The broader lesson is not that Claude independently decided to attack companies. Human threat actors directed and used the AI as part of their operations. Anthropic says humans still made important decisions such as target selection and monetization, while AI could handle much of the technical execution.
The report highlights a new cybersecurity concern: AI can compress the time, expertise and labor required to conduct sophisticated attacks. An attacker with a stolen credential can potentially use an AI agent to understand an unfamiliar environment, interact with APIs, write scripts and repeatedly execute tasks with limited manual intervention.
The emerging attack chain can look like this:
Stolen credential → AI reconnaissance → API abuse → privilege escalation → automated data extraction.
For defenders, this makes strong credential protection, least-privilege access, token monitoring, API security and continuous detection increasingly important.
AI agents can dramatically increase productivity—but the same autonomy that makes them useful can also increase the speed and scale of cyberattacks.