Cyberattacks that previously required large, specialized teams can increasingly be carried out by just a handful of people. That’s because AI takes over much of the time-consuming work, according to Anthropic in a new report on the misuse of its Claude models.
Attackers don’t even need new attack techniques, reports SiliconANGLE. Stolen login credentials and vulnerable systems remain key entry points. The main difference is how quickly AI helps identify targets, execute tasks, and adapt attack methods.
For example, Anthropic observed a Russia-linked group attacking multiple drone suppliers. The attackers collected email accounts and stole drone software. As soon as security software detected their malware, Claude was deployed to modify the attack code and redistribute it.
Cybercriminals seeking financial gain also benefit from this automation. In one incident, it took only about three hours to progress from a stolen developer token to full administrative access to a cloud environment. In another campaign, attackers stole thousands of authentication tokens from dozens of corporate environments.
AI companies are becoming targets themselves
Meanwhile, the AI industry has proven to be an attractive target. Anthropic describes a campaign in which attackers attempted to obtain API keys from multiple AI providers via an evaluation environment. Another campaign targeted about thirty AI companies within a few days, aiming to gain access to a yet-to-be-released Claude model. Anthropic states that these attack attempts were unsuccessful.
In addition, the company accuses several Chinese AI developers of using Claude output to train their own models. In doing so, they reportedly forwarded conversations with Claude on a large scale. Anthropic names, among others, Alibaba-affiliated parties, Moonshot AI, and DeepSeek.
Cybersecurity is thus becoming an AI race
Anthropic’s key conclusion is that AI is changing the scale of cyberattacks. A single operator can execute multiple attack vectors simultaneously, while human intervention remains necessary primarily for decision-making and oversight.
For organizations, this means that traditional defense is increasingly less about blocking a single attack. Security teams must account for attackers who are continuously and automatically trying new routes.
Anthropic has blocked the accounts involved and shared information about the campaigns with governments and security partners. The company is also updating Claude to make it harder for internal reasoning steps to be leaked.