Back to wire
AI·Article·Confirmed

Anthropic says AI attacks are shifting from chat assistance to multi-agent execution

Anthropic says a majority of the cyber operations in its September threat report used AI for direct execution or orchestration rather than only conversational assistance, including multi-agent reconnaissance, exploitation and data exfiltration. The report covers selected misuse observed from December 2025 through August 2026 and explicitly warns that its cases are notable examples, not prevalence estimates.

Published 10 Sept 2026, 02:00 · Updated 17 Sept 2026, 16:27

From assistant to orchestrator

Anthropic says malicious users are increasingly placing Claude inside agentic attack workflows rather than using it only as a conversational adviser. In its September threat-intelligence report, covering activity disrupted between December 2025 and August 2026, the company says a majority of the cyber operations it describes involved AI directly executing or orchestrating parts of the attack chain, including reconnaissance, exploitation and data exfiltration.

Humans still retained consequential decisions such as selecting targets and reviewing stolen material. Anthropic also separates autonomy from severity: a highly autonomous workflow can increase speed and scale without necessarily making an intrusion more damaging, while some of the most serious compromises in the report were still directed step by step by people.

Multi-agent workflows moved into live operations

One case, tracked by Anthropic as GTG-20006, used customised AI-driven workflows across malware development, infrastructure acquisition, phishing, persistence, command-and-control and exfiltration. Anthropic says agents monitored whether security products detected deployed malware and, when they did, modified and rebuilt the tooling until it again evaded the observed detections.

Another investigation, GTG-10007, involved what Anthropic calls agent swarms: a lead agent decomposed reconnaissance and post-exploitation work across multiple subagents, while campaign memory preserved targets, credentials and standing instructions between sessions. The company says some collection and token-renewal jobs ran on schedules with little or no human intervention.

The report spans more than cyber intrusion

The report also documents influence operations, surveillance, scams, conventional-weapons work, biological misuse and illicit model distillation. AP independently reported that Anthropic blocked attempts to use Claude for research that could have supported harmful biological work, and that the company has tightened safeguards around dual-use biological queries in newer models.

In France, Le Monde examined one of the report’s cases involving a lone hacker who allegedly targeted 42 organisations associated mainly with the far right and gained internal access to at least 14. Le Monde reported that some details matched a previously known compromise of the magazine Frontières, while Anthropic attributed the broader operation from its own service telemetry.

What the evidence establishes and what it does not

Anthropic is the primary source for actor attribution, the scale of Claude use and claims about how much AI increased attacker capability. The company had direct visibility into activity on its own systems, but much of the underlying evidence is not independently reproducible from the public report. The cases should therefore be read as vendor threat intelligence, with secondary reporting able to corroborate only selected victims or events.

Anthropic explicitly says the cases are selected for being notable or novel and are not representative of typical misuse. The report does not provide a denominator for how often Claude is used maliciously, nor does it show that most cyberattacks in general are now autonomous. Its stronger finding is narrower: among the serious operations Anthropic chose to document, agentic execution and orchestration had moved beyond demonstrations into operational workflows.

Source trail

4 sources · 1 primary · 2 secondary · 1 community