
Anthropic put out its most detailed threat report to date on September 10, called "Detecting and countering misuse of AI." It covers activity the company disrupted between December 2025 and August 2026 across seven harm areas, and the cyber section is the one worth reading closely. The models involved were Claude Haiku, Sonnet, and Opus. Anthropic says none of the cyber misuse used its Fable or Mythos models, and I will come back to why that matters.
The report's own section heading states it plainly: "sophisticated attacks no longer require sophisticated attackers."
The attacks themselves are familiar. Stolen credentials, unpatched edge devices, exposed services, SQL injection, phishing. What changed is who can run them and how fast. The report frames it as unit economics: the labor that used to separate a well-funded state team from a lone operator, meaning reconnaissance, tooling, exploitation, and data processing, is now handed to models running in harnesses at machine speed and in parallel. Anthropic's own words are that the distinguishing feature between a state actor and a criminal is "no longer sophistication but intent."
A few of the cases make the point concrete.
A Russian espionage actor, tracked as GTG-20006 and consistent with public reporting on Midnight Blizzard, wired AI into the evasion loop. When a security product flagged their malware, agents rebuilt and redeployed it automatically, iterating until it went undetected, then staged it for live operations. Anthropic's phrase for the result is that AI "inverted the cost back onto defenders." A capable adversary can now close the loop faster than defenders can write and ship a new detection.
A financially motivated cluster tied to ShinyHunters ran breaches in two to three hours. One affiliate downloaded 1.8 million Android apps across ten cloud workers, decompiled them, and scanned for hardcoded secrets. Another dumped over 2,100 cloud token sets across more than 40 corporate tenants in about 34 hours, and Anthropic notes AI agents "performed nearly all of the work."
A Chinese-speaking group, GTG-10007, run in part by two undergraduates in Hunan, kept an autonomous vulnerability research program pointed at a major endpoint security product. Loading firmware into a decompiler through a tool server, the workflow surveyed the binary, formed vulnerability hypotheses against a memory it curated over time, wrote exploit code, and tested it against lab copies until it worked. One workflow iterating on network appliances produced more than a dozen possible zero-day findings in a single month.
Anthropic is careful about a distinction that gets lost in the headlines. The cases run the full range of autonomy, from Claude used as a coding assistant for malware, to Claude executing commands under a human making each targeting call, to multi-agent frameworks running for hours or days with almost no supervision. But autonomy multiplies scale and speed, and it lowers cost. It does not by itself determine severity. Some of the most serious compromises in the report came from operations where a human directed every step.
Put plainly, AI compresses the cost side of an attacker's math while leaving the payoff about the same. That makes marginal targets worth hitting and pushes everyone toward higher-volume, lower-touch campaigns. One French-speaking hacktivist, working alone, built a doxxing platform loaded with tens of millions of records including national health identifiers, ran it for a month entirely on stolen API keys, and exfiltrated political party donor and member data from 14 organizations. One person did the work of a team.
The part device makers should sit with is that the AI supply chain has itself become a target. Stolen API keys give an attacker three things at once: resale value, free compute on someone else's bill, and cover, because the activity traces back to the legitimate owner. One actor hit roughly 30 AI companies in about four days trying to reach a pre-release Claude model, switching to each victim's own stolen keys as they went. Others stood up fake AI reseller sites that proxied traffic to a different model while harvesting credentials, some spoofing popular coding harnesses to plant credential stealers. In every case Anthropic examined, the keys were stolen from customers' environments, not from Anthropic's own systems.
The guidance is blunt and correct: treat AI keys and agent integrations with the same seriousness as production credentials, because attackers already do.
One finding here ties directly to the export-control fight from earlier this year. Anthropic reports that Chinese labs ran distillation campaigns to pull cyber capability out of US frontier models, and that one of them, Zhipu, tried to target Fable's cyber capabilities first, then gave up because Fable's strengthened cyber safeguards degraded the attack, and moved to weaker models instead. None of the disrupted cyber operations used Fable or Mythos.
Zhipu choosing an easier tool is a real, measurable data point in the argument about whether hardened frontier models help or hurt defense. The safeguards worked well enough that the adversary walked away. It does not settle the debate, but it is the first evidence I have seen that a safeguard actually changed an attacker's behavior.
None of the techniques in this report are new. The change is that the floor came up. A lone operator now reaches capability that used to take a funded team, and threat modeling that leaned on "who has the resources to do this" no longer narrows the field. For anyone building or defending devices, the front-of-mind items are the evasion loop that ages out static detections faster than you can deploy them, the autonomous foundry pointed at firmware and appliance code, and the API keys and agent integrations that are now first-class targets. The report is the clearest public accounting of it so far, and the trend line only points one way.
---
Sources: Anthropic, "Detecting and countering misuse of AI: September 2026," September 10, 2026. Case identifiers, figures, and quotes are from that report. Comparison points from Google Threat Intelligence Group, "From Prompting to Autonomy," September 8, 2026.