Signals · Threat Landscape
Anthropic's threat report shows attack labour has been automated, not attack skill
Anthropic disrupted operations where lone criminals ran state-grade intrusions, with breaches completed in two to three hours.
by Jo·3 min read·
Anthropic published its latest threat intelligence report on Thursday, covering malicious use of Claude that its Threat Intelligence team disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation. The headlines went to the biological misuse cases. The line that should move an operator's position is buried in the cyber section: "For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation."
The labour gap closed, not the skill gap
Anthropic's own framing is economic, not technical. "None of the operations in this report depended on some entirely novel technique that defenders have never seen," the report states. The attacks were stolen credentials, unpatched edge devices, exposed services, SQL injection, phishing. What changed is that reconnaissance, exploitation, tool development and data processing — the labour that used to separate a state service from a lone operator — are now delegated to models running in harnesses at machine speed and in parallel.
The numbers Anthropic reports are the proof. Breaches completed in two to three hours, and dozens of victims handled in parallel by individual operators. One compromise escalated from a single stolen developer token to full administrative control of a victim's cloud environment in roughly three hours. In another, a session-store dump produced over 2,100 Azure AD token sets spanning more than 40 corporate tenants in about 34 hours, with AI agents performing nearly all the work.
One French-speaking criminal operator ran a credential-harvesting pipeline across ten AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs, decompiled them and scanned them for hardcoded secrets. A suspected Russian state-nexus actor, which Anthropic assesses as consistent with public reporting on Midnight Blizzard, targeted more than 20 distinct organisations and, in one intrusion of a North African government technology authority, exfiltrated more than 300,000 national identity records and the commercial registry data of more than half a million companies.
A hacktivist, a financially motivated crew and a state espionage operator all ran the same methodology. Anthropic's conclusion: "The main distinguishing feature between these classes of actors is no longer sophistication but intent."
Your AI credentials are now the loot
The second finding is the one most teams have not priced in. Anthropic describes a criminal AI supply chain in which "access to AI in the form of compromised API keys, session tokens, and devices has increasingly become the sole objective of multiple criminal groups." Stolen keys are sold through brokers into fraudulent reseller networks and rotated until exhausted.
One group, tracked as GTG-50021, sold discounted Claude access that was silently proxied to a different model while its tooling installed a credential harvester on the customer's machine and stole their Anthropic credentials for onward sale. Other operators distributed malware spoofing popular AI harnesses, including Claude Code, and kept harvesting new session tokens after the first set was reset.
Note what the humans kept. Anthropic is explicit that operators remained heavily involved in target selection, monetisation of findings, and review of results. Even in a criminal economy, the automated layer is execution and the retained layer is judgment about what is worth doing. That is the same line running through every legitimate industry right now.
Your Next Move
Inventory every place an AI credential lives. API keys and session tokens on developer laptops, in CI pipelines, in mobile builds, in vendor integrations. Anthropic's report shows keys harvested from decompiled apps and from enterprise software vendors, then used for weeks against third parties. Rotate anything that has been static for a quarter and set expiry by default.
Buy AI access only from the vendor. Discounted frontier-model resellers were the delivery mechanism in Anthropic's cases. If someone in your organisation is expensing cheap Claude or GPT access through an intermediary, treat that account as already compromised.
Stop grading threats by apparent sophistication. Anthropic says the capabilities in this report should be assumed available to any motivated actor. Rewrite your incident triage so that a competent multi-victim campaign no longer implies a well-resourced adversary, and so that detection assumes an attacker who can rebuild malware faster than you can publish a signature.
I build systems like the one publishing this site. → Work with me
About the author
Jo
Jo runs The War Room: strategic intelligence for operators navigating AI disruption, influence, and empire-building.
Sources
Get the Briefing
Want more intelligence like this?
Get the free AI Survival Kit — 7 strategies from 13 playbooks.
More in Signals
See allSignals · Capability Displacement
AI agents can run the experiments but not choose them
4 min read
Signals · Capability Displacement
The best coding agent finished 38.8% of real enterprise tasks
4 min read
Signals · Power
Anthropic Put "Activism" on Its Threat List, and Wrote It Into a Job Posting
3 min read