> ## Content Index
> Fetch the complete content index at: https://www.theamericanquorum.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Anthropic Says AI Agents Are Orchestrating Cyberattacks
- URL: https://www.theamericanquorum.com/anthropic-says-ai-agents-are-orchestrating-cyberattacks/
- Published: 2026-09-11T06:30:08.000Z
- Updated: 2026-09-11T06:30:08.000Z
- Description: Anthropic says AI agents are executing large portions of cyberattacks, surveillance and model theft. The cases show lower operational barriers, but most evidence remains company-reported and only partly corroborated.
- Author: News Desk
- Tags: Tech

More than 20 organizations appeared in the targeting plans of a suspected Russia-linked espionage operation that used artificial intelligence across phishing, malware development, credential theft and data exfiltration, according to a new [threat report](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=theamericanquorum.com) from Anthropic. The September 10 disclosure describes a broader shift from criminals asking chatbots for advice to AI agents executing and coordinating substantial portions of real cyber operations.

Anthropic said it identified and disrupted misuse of its Claude models between December 2025 and August 2026 across seven categories: cyber operations, surveillance, influence campaigns, fraud, biological misuse, conventional weapons work and unauthorized model distillation. In several cyber cases, multi-agent systems performed reconnaissance, exploitation and theft in parallel while people selected targets and reviewed results. That does not make the attacks autonomous in every meaningful sense, but it changes their speed, staffing and economics.

The findings are important because they describe observed activity rather than a laboratory forecast. They also require caution. Anthropic selected the cases, investigated activity on its own platform and withheld many names and technical details. Most allegations have not been independently verified, and the company emphasized that the examples were unusual rather than representative of ordinary Claude use. [AP](https://apnews.com/article/anthropic-ai-threat-bioweapon-russia-00266dca90e4f8853f669648998d3bda?ref=theamericanquorum.com) reported that Anthropic said it banned the identified accounts and shared information with authorities and industry partners.

## AI moves from assistant to operator

The report’s central technological claim is that AI is crossing from content generation into operational control. Anthropic said a majority of the described cyber campaigns used models for direct execution or orchestration, not merely for drafting code. Agents could inspect a victim environment, write and run scripts, interpret results, revise tactics and continue until a broader objective was achieved.

One financially motivated intrusion allegedly escalated from a stolen developer token to administrative control of a cloud environment in roughly three hours. Another operation extracted data belonging to about 200 downstream customers of a compromised software provider and gathered more than 2,100 cloud access tokens spanning over 40 corporate tenants in about 34 hours. Anthropic said AI agents performed nearly all the work in that cluster, although humans remained responsible for choosing victims and monetizing stolen material.

The methods themselves were generally familiar: exposed credentials, phishing, unpatched services, malicious scripts and abuse of legitimate cloud interfaces. What changed was the labor required to connect those steps. Instead of assigning reconnaissance, coding, exploitation and data processing to several specialists, an operator could delegate much of that sequence to a model running through software tools. The consequence is not necessarily a novel class of vulnerability; it is a lower cost per attempted breach.

That distinction aligns with [Reuters](https://www.reuters.com/legal/litigation/anthropic-disrupts-russian-chinese-ai-campaigns-targeting-its-claude-models-2026-09-10/?ref=theamericanquorum.com) reporting that humans often functioned as supervisors rather than hands-on operators. AI did not independently decide whom to attack or why. It expanded the amount of technical work a small group could perform, allowing multiple targets and changing environments to be handled simultaneously.

## A Russia-linked campaign shows the mechanism

Anthropic attributed one operation to a Russian-speaking actor whose behavior and targets were consistent with public reporting on Midnight Blizzard, a group the United States and Britain have linked to Russia’s Foreign Intelligence Service. The operation focused heavily on Ukrainian government, military and diplomatic targets, as well as drone makers, embassies, defense organizations and people connected to U.S. foreign policy.

The actor allegedly used AI to create phishing infrastructure, run commands against compromised systems, collect credentials, move across networks and organize large volumes of stolen data. Its tools monitored whether security products detected malware; when they did, agents modified and rebuilt the code until it again evaded those defenses. That closed-loop process threatens to shorten the period in which a newly deployed detection reliably imposes costs on an attacker.

Independent reporting supports important parts of the campaign’s surrounding context. In July, [Microsoft](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/?ref=theamericanquorum.com) described a related operation that compromised hospitality networks, manipulated captive-portal traffic and delivered malware through fake update prompts. Microsoft said the actor used AI in a significant portion of the campaign and thanked Anthropic and OpenAI for assisting its investigation.

The overlap matters because it provides evidence outside Anthropic’s own telemetry for the actor, infrastructure and tactics. It does not independently confirm every new claim in Anthropic’s report. Attribution in cyberespionage is inherently probabilistic, and the report used an internal designation for the observed operator. The safest conclusion is that multiple companies saw connected Russian-aligned activity using AI to accelerate established intrusion techniques.

## Surveillance and weapons work widen the risk

The report goes beyond network intrusions. Anthropic said government-linked actors used Claude to build surveillance systems, analyze social-media records and identify potential targets. In one example, a consultant working for Malian security authorities allegedly designed a system capable of collecting data from mobile operators and producing individual dossiers. In another, a Chinese religious-affairs intelligence office reportedly used an AI assistant to produce thousands of investigations each month.

[Axios](https://www.axios.com/2026/09/10/anthropic-claude-government-surveillance-threats?ref=theamericanquorum.com) reported that the surveillance cases used older Haiku, Sonnet or Opus models rather than Anthropic’s newer Fable or Mythos-class systems. Anthropic said it closed the accounts, but its threat-intelligence chief acknowledged that some operators shifted to locally hosted or open models. Platform enforcement can therefore raise costs without necessarily ending the underlying program.

Anthropic also described five cases involving biological research that could have both beneficial and dangerous uses. One involved planning experiments related to chikungunya transmissibility and immune evasion; another concerned avian-influenza adaptation. The company explicitly said it did not know whether the scientists intended harm and withheld their identities and countries. The [Guardian](https://www.theguardian.com/technology/2026/sep/10/anthropic-report-details-ai-misuse?ref=theamericanquorum.com) noted that the company presented these as potential dual-use risks, not evidence that a biological weapon was produced.

The limits are essential. A model helping draft a grant application is not the same as conducting laboratory work, and an alarming query does not prove operational capability. Anthropic nonetheless said it could no longer provide the same assurance of limited biological assistance that it had made about older systems. The company has introduced broader restrictions for newer models, including a [safeguard framework](https://www.anthropic.com/news/fable-safeguards-jailbreak-framework?ref=theamericanquorum.com) designed to reduce harmful cyber and scientific assistance.

## Model extraction becomes an industrial operation

A separate portion of the report concerns companies allegedly trying to copy Claude’s capabilities. Anthropic attributed more than 151 million exchanges between May and July to an Alibaba-linked distillation campaign, peaking near 3 million interactions a day across thousands of accounts. Distillation can be a legitimate training method, but Anthropic characterized this activity as covert, unauthorized access designed to reproduce proprietary reasoning abilities.

The company also accused Moonshot and DeepSeek of routing live customer requests through Claude while users believed they were interacting with those companies’ models. Some prompts allegedly contained sensitive commercial, government or military information. [Business Insider](https://www.businessinsider.com/china-ai-labs-millions-distillation-attacks-anthropic-claude-2026-9?ref=theamericanquorum.com) reported that the combined activity described by Anthropic approached 190 million interactions. The named companies had not publicly supplied detailed responses when the reports were published.

This is both an intellectual-property dispute and a privacy problem. If a service silently forwards customer prompts to a third party, users can lose control over where sensitive material is processed. For AI providers, stopping the practice requires more than blocking high-volume traffic: the reported operators used residential proxies, disposable accounts, virtual cards and stolen API credentials to resemble ordinary demand.

## Defenders need different measurements

The report suggests that traditional indicators of attacker sophistication are becoming less reliable. Polished code, rapid adaptation and simultaneous campaigns once implied a large or highly skilled team. Agentic systems can now reproduce some of those characteristics for smaller groups. Security teams will need to measure machine-paced iteration, coordinated API activity, token abuse and unusual tool sequences rather than infer capability primarily from the apparent quality of malware.

AI companies also face a transparency problem. They possess the clearest platform-level evidence of abuse, yet they have commercial incentives to emphasize successful detection and minimize undetected harm. Independent researchers and governments rarely have equivalent access to prompts, account networks and internal classifiers. Useful disclosure therefore requires enough technical detail for outside corroboration without publishing instructions that make attacks easier.

Anthropic’s report does not prove that AI has replaced skilled attackers or that most cybercrime is autonomous. It does show multiple operations in which models reduced the labor needed to move from stolen access to exploitation and theft. The practical test now is whether providers and defenders can detect coordinated agent behavior as quickly as attackers can adapt it. The September cases establish that the contest is already operational, not hypothetical.