From assistant to orchestrator
Anthropic says malicious users are increasingly placing Claude inside agentic attack workflows rather than using it only as a conversational adviser. In its September threat-intelligence report, covering activity disrupted between December 2025 and August 2026, the company says a majority of the cyber operations it describes involved AI directly executing or orchestrating parts of the attack chain, including reconnaissance, exploitation and data exfiltration.
Humans still retained consequential decisions such as selecting targets and reviewing stolen material. Anthropic also separates autonomy from severity: a highly autonomous workflow can increase speed and scale without necessarily making an intrusion more damaging, while some of the most serious compromises in the report were still directed step by step by people.
Multi-agent workflows moved into live operations
One case, tracked by Anthropic as GTG-20006, used customised AI-driven workflows across malware development, infrastructure acquisition, phishing, persistence, command-and-control and exfiltration. Anthropic says agents monitored whether security products detected deployed malware and, when they did, modified and rebuilt the tooling until it again evaded the observed detections.
Another investigation, GTG-10007, involved what Anthropic calls agent swarms: a lead agent decomposed reconnaissance and post-exploitation work across multiple subagents, while campaign memory preserved targets, credentials and standing instructions between sessions. The company says some collection and token-renewal jobs ran on schedules with little or no human intervention.
The report spans more than cyber intrusion
The report also documents influence operations, surveillance, scams, conventional-weapons work, biological misuse and illicit model distillation. AP independently reported that Anthropic blocked attempts to use Claude for research that could have supported harmful biological work, and that the company has tightened safeguards around dual-use biological queries in newer models.
In France, Le Monde examined one of the report’s cases involving a lone hacker who allegedly targeted 42 organisations associated mainly with the far right and gained internal access to at least 14. Le Monde reported that some details matched a previously known compromise of the magazine Frontières, while Anthropic attributed the broader operation from its own service telemetry.
What the evidence establishes and what it does not
Anthropic is the primary source for actor attribution, the scale of Claude use and claims about how much AI increased attacker capability. The company had direct visibility into activity on its own systems, but much of the underlying evidence is not independently reproducible from the public report. The cases should therefore be read as vendor threat intelligence, with secondary reporting able to corroborate only selected victims or events.
Anthropic explicitly says the cases are selected for being notable or novel and are not representative of typical misuse. The report does not provide a denominator for how often Claude is used maliciously, nor does it show that most cyberattacks in general are now autonomous. Its stronger finding is narrower: among the serious operations Anthropic chose to document, agentic execution and orchestration had moved beyond demonstrations into operational workflows.