Articles
September 21, 2026

AI Is Changing the Economics of Cyberattacks: Key Insights from Anthropic’s September 2026 Threat Intelligence Report

AI Is Changing the Economics of Cyberattacks: Key Insights from Anthropic’s September 2026 Threat Intelligence Report

Artificial intelligence is changing not only how cyberattacks are carried out, but also who can carry them out.

Anthropic’s September 2026 Threat Intelligence Report documents a shift from AI being used as a simple assistant to becoming an active orchestrator of cyber operations.

The report covers malicious activity observed and disrupted between December 2025 and August 2026, involving suspected state-sponsored groups, financially motivated criminals, and politically motivated actors. Across the cases, AI accelerated activities across the cyber kill chain – from reconnaissance and phishing to exploitation, credential theft, data processing, and exfiltration.

From assistant to orchestrator

One of the report’s most important findings is that attackers are increasingly using AI beyond simple question-and-answer interactions.

In the cases investigated by Anthropic, AI was integrated into multi-agent workflows capable of performing reconnaissance, exploitation, tool development, credential harvesting, data processing, and exfiltration. Humans remained involved in setting targets and reviewing results, but many operational tasks could be delegated to AI and executed in parallel.

Anthropic describes this as a shift from “assistant to orchestrator.” The impact is particularly significant because AI can increase the speed, scale, and depth of operations across multiple stages of an attack — not just automate a single task.

Sophisticated attacks no longer require sophisticated attackers

AI is also reducing the gap between highly resourced threat actors and less experienced operators.

According to Anthropic, AI has increasingly reduced the labor and tooling gap that once separated state-sponsored operations from individual attackers. Reconnaissance, tool development, exploitation, and data processing can all be accelerated with AI, allowing actors with fewer resources to conduct operations that previously required teams of skilled specialists.

Publicly available offensive AI frameworks are contributing to this trend by providing reusable structures for automating different stages of the cyber kill chain.

The result is a change in how organizations should assess threats: the apparent sophistication of an attack may no longer reliably indicate the sophistication or resources of the attacker behind it.

Case study: AI-assisted espionage targeting Ukraine and Europe

One of the report’s most significant examples is GTG-20006, an operation Anthropic says is consistent with public reporting linking the actor to the Russian state-sponsored group Midnight Blizzard.

The actor used customized AI-driven workflows across much of the attack lifecycle, including infrastructure acquisition, phishing, persistence, credential theft, and data exfiltration. AI was also used to monitor whether malware was being detected by security products. When a tool was detected, AI agents could modify and rebuild it and continue iterating until the detection was avoided.

Anthropic identified more than 20 organizations in the actor’s operational planning, reconnaissance, and live operations. Targets included government ministries, defense and intelligence organizations, diplomatic missions, think tanks, and defense-industrial companies, with activity concentrated in Ukraine and Europe.

Ukraine and military drone technology were recurring areas of interest. The actor targeted drone manufacturers and suppliers, exported mailboxes from drone component manufacturers, and obtained a proprietary software development kit for a drone vision system. The stolen information was then used to reconstruct aspects of the system’s architecture, hardware, supplier dependencies, and other product details.

The operation also demonstrated how attackers can use third-party infrastructure as an entry point. At least three hospitality technology providers were compromised, allowing the attackers to modify DNS records associated with hotel guest Wi-Fi networks. This enabled them to redirect traffic and deliver malware to selected victims. Microsoft independently reported related activity under the name CaptiveCrunch.

Case study: AI-powered mass exploitation and data theft

Another cluster tracked as GTG-50014, associated by Anthropic with suspected ShinyHunters affiliates, demonstrates how AI can accelerate opportunistic cybercrime.

The operators used automated pipelines to search for exposed credentials, API keys, and tokens across applications, code repositories, containers, and other online resources. In one example, an operator downloaded approximately 1.8 million Android APKs, decompiled them, and scanned them for hardcoded secrets.

Once valid credentials were obtained, AI was used to help attackers understand unfamiliar environments, expand access, create tools, retrieve information, and move across connected customer environments.

The scale of some incidents was substantial. In one case, attackers exfiltrated more than 1 TB of data from a technology provider. In another, a supply-chain compromise gave attackers access to data belonging to approximately 200 downstream customer organizations.

The speed of these operations is equally significant. Anthropic reports that one enterprise software breach progressed from initial access to bulk data theft within hours. In another case, attackers escalated from a single stolen developer token to full administrative control of a victim’s cloud environment in approximately three hours.

The AI supply chain is becoming part of the attack surface

The report also highlights a growing security concern: attackers are targeting not only traditional infrastructure, but the AI supply chain itself.

AI API keys and credentials can provide access to AI services and computing resources. In the cases investigated by Anthropic, stolen AI API keys were reused in subsequent attacks against other organizations.

This means that AI credentials and integrations need to be treated as security-sensitive assets, just like other production credentials.

As organizations deploy more AI applications, agents, APIs, and third-party AI services, each integration can introduce another potential access point. Securing these connections therefore becomes part of the broader enterprise security strategy.

What this means for cybersecurity

The main takeaway from Anthropic’s findings is not that AI has created completely new types of cyberattacks. Rather, AI is changing the economics and operational tempo of attacks.

Attackers can automate work that previously required significant expertise and manpower. They can investigate unfamiliar environments faster, operate against multiple targets simultaneously, process large amounts of stolen data, and adapt their tools when defenses detect them.

For defenders, this creates a challenge for security models that rely heavily on static detection and periodic response. In the GTG-20006 case, for example, AI-assisted workflows could identify when malware had been detected and modify the tooling to bypass those detections. Anthropic describes this as effectively shifting some of the operational cost back onto defenders.

As AI becomes more autonomous, organizations therefore need visibility not only into their traditional infrastructure, but also into what AI systems and agents are doing, what data they can access, and which tools and systems they interact with.

Securing the next generation of AI-powered operations

The evolution described by Anthropic points to a broader shift in cybersecurity: AI itself is becoming part of the security landscape.

As organizations deploy increasingly autonomous AI systems, security teams need to be able to govern AI usage, monitor activity at runtime, and understand how AI agents interact with enterprise data, applications, tools, and external environments.

Witness AI helps organizations address these challenges with capabilities for AI governance, real-time runtime protection, and security for AI agents and MCP environments.

By providing greater visibility and control over AI activity, Witness AI helps organizations manage the risks that emerge as AI moves from simple assistants toward autonomous systems capable of taking actions across enterprise environments.

When AI increases the speed and autonomy of cyber operations, securing AI becomes an essential part of securing the enterprise itself.

Sources

Anthropic, Detecting and countering misuse of AI: September 2026. The report covers malicious activity identified and disrupted between December 2025 and August 2026.

Ready to secure your AI-powered environment?

As AI becomes more autonomous, organizations need more than visibility into traditional threats. They need to understand what their AI systems and agents are doing, what they can access, and how to control their activity.

Talk to our team to learn how you can gain visibility and control over AI activity across your organization!

Fill out the form to book a consultation/demo

Thank you! We’ll get back to you soon

We have received your message and will get back to you as soon as possible. Our team is dedicated to providing the best support and we appreciate your patience.

Oops! Something went wrong.
Subscribe To Our Weekly Newsletter - Cybersecurity X Webflow Template