A Anthropic identified criminal groups and government-linked operators using Claude models to automate stages of cyberattacks, including target reconnaissance, exploitation of vulnerabilities, credential theft, and data exfiltration. The cases, disclosed by the company on Thursday (10), span activities detected between December 2025 and August 2026.

According to the company, some of these operations moved beyond using AI merely as a coding assistant. Structures with multiple agents began executing attacks against several victims simultaneously, for hours or days, with human intervention limited mainly to choosing targets and analyzing results.

In one of the investigated campaigns, a group tracked as GTG-20006 used AI-based workflows to automate everything from infrastructure preparation and phishing to persistence, command and control, and information extraction. More than 20 organizations appeared in the group's planning and operations, including government agencies, defense and intelligence entities, embassies, and companies linked to the military industry.

The operator also used agents to check whether its malware had been detected by security tools. When that happened, the system could automatically modify and rebuild the code until the new versions were no longer identified by the monitored defenses.

AI agents expand the scale of attacks

Anthropic also found financially motivated criminals using Claude in intrusions against software providers. In one of the cases, the compromise of a SaaS company allowed access to data from about 200 client organizations. The attackers also extracted more than 2,100 sets of Azure AD tokens, linked to more than 40 corporate environments, in approximately 34 hours.

The attack lifecycle shared by the clusters of suspected ShinyHunters affiliates that we disrupted, from harvesting credentials to extortion
The attack lifecycle shared by the clusters of suspected ShinyHunters affiliates that we disrupted, from harvesting credentials to extortion

Another attack against a technology provider resulted in the extraction of more than 1 terabyte of data, including hundreds of thousands of national identifiers and millions of payment card records. In an airline, the intruders reached systems that stored tens of millions of passenger records.

The company says that the main change is not necessarily in the techniques employed, which continue to include stolen credentials, phishing, exposed services, and known vulnerabilities, but in the ability to automate tasks that previously required specialized teams. Reconnaissance, tool development, exploitation, and processing of large volumes of data began to be delegated to AI models and executed in parallel.

The attack lifecycle and AI integration
The attack lifecycle and AI integration

Anthropic said it blocked the accounts associated with the identified operations, reinforced its detection mechanisms, and shared information with authorities and industry companies when necessary. The company assesses that the spread of agent-based attack structures could allow individual operators to execute campaigns previously restricted to groups with more resources and technical knowledge.

More from Radar