Anthropic describes cyberattacks coordinated by AI agents but directed by people
The new development is not simply an attacker consulting a chatbot, but delegating connected parts of an operation to it. In its threat intelligence report, announced on September 10, Anthropic says it identified campaigns that used Claude to coordinate reconnaissance, vulnerability exploitation, and data extraction. The company describes greater operational autonomy, but also draws a crucial distinction: people still make decisions about targets, monetization, and reviewing results.[1][3]
The document covers activity Anthropic says it disrupted between December 2025 and August 2026. It is neither a census of cybercrime nor a representative sample: the company itself explains that it selected particularly notable and novel examples. CyberScoop reported on its conclusions on September 10, in an article by Greg Otto.[1][2]
From answering questions to coordinating tasks
According to Anthropic, most operations described incorporated direct execution or orchestration through AI, beyond question-and-answer exchanges. Systems could divide work among agents and connect different stages of an intrusion. That organization matters because it enables the automation of successive tasks, rather than simply producing text or suggesting code.[1]
In the case designated GTG-20006, Anthropic describes workflows that monitored whether security products detected malicious tools and, when that happened, modified and rebuilt them. The company connects its attribution with public reporting on Midnight Blizzard; that identification is Anthropic’s assessment, not an independent conclusion by this newsroom. According to the report, the human operator also adjusted the instructions organizing those workflows.[1]
Another example illustrates the difference between automating a task and sustaining a campaign. Anthropic describes an intrusion into a software-as-a-service provider in which access-token sets were extracted from more than 40 corporate tenants in approximately 34 hours. The company says agents performed nearly all the work. CyberScoop covers the same episode, but its reporting does not constitute an independent audit of the underlying records.[1][2]
Autonomy does not mean the absence of human direction
The report presents a spectrum: from Claude as an engineering assistant to multi-agent frameworks operating for hours or days with minimal supervision. It also describes scheduled tasks with no human involvement during execution. That does not amount to demonstrating that the system independently chose the purpose of the entire campaign.[1]
Anthropic emphasizes that operators retained particularly important decisions, including selecting victims, monetizing findings, and reviewing results. It adds a warning that helps avoid misleading headlines: autonomy and harm are separate dimensions. Several of the most serious intrusions it documents involved a person directing every step.[1]
These cases therefore do not justify claiming that all attackers already operate autonomously or that any user can reproduce their results. The evidence presented describes specific operations observed by one provider, with different degrees of delegation.
What the publication establishes and what remains open
The scope of the evidence remains limited by its origin. Anthropic is both the model provider and the source of findings about intrusions, data volumes and attributed identities. CyberScoop’s coverage reports those findings; it does not provide a second forensic investigation of the same incidents. The cases should be read with that distinction in mind, even when they describe concrete consequences for businesses and their customers.
Anthropic also maintains that the attack techniques remained familiar: stolen credentials, exposed services, unpatched systems, and phishing. Its argument is that delegating tasks to models changes the economics of offensive work. That interpretation deserves attention, but should not become a universal measurement of increased risk.[1]
From a social and strategic perspective, the useful question is who directs the operation, what capability they delegate, and who bears the harm. For defending organizations, the cautious reading is to treat automation as a factor that can accelerate familiar threats, without abandoning basic controls or confusing speed with inevitability. This is an editorial interpretation of the cases, not a measure of defensive effectiveness established by this report.
Sources
[1] Anthropic, *Detecting and countering misuse of AI: September 2026*: Read More Greg Otto, CyberScoop, *AI lets small actors run state-level hacking campaigns, Anthropic report finds*, September 10, 2026: Read More Anthropic, official news index, September 10, 2026 entry: Read More by Lía Torres — Social and strategic perspective.
Sources: Anthropic, CyberScoop