Anthropic Analysis of AI-Enabled Cyber Threats (2025-2026)

Anthropic has analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026 to determine how AI is altering the landscape of cyberattacks. The study concludes that AI is increasing the danger of threat actors by enabling them to execute complex, post-compromise operations and orchestrate autonomous attack chains that bypass traditional risk assessment methods.

AI Shifts Attack Focus to Post-Compromise Activities

AI is increasingly being used to execute the later, more complex stages of a cyberattack rather than just initial access. While 67.3% (560 of 832) of analyzed accounts used AI to write malware, a smaller portion (6.5% or 54 actors) utilized AI for "lateral movement" to navigate deep within compromised networks.

Key trends in AI application include:

  • Increased Risk Levels: The share of actors classified as medium risk or higher rose from 33% in the first six months of the study to 56% in the second six-month period, a roughly 1.7-fold increase.
  • Shift in Tactics: AI-assisted phishing (initial access) fell by 8.6%, while the use of AI for account discovery (identifying valid accounts inside a compromised environment) rose by 8.9%.
  • Lowering the Technical Bar: AI allows less sophisticated actors to perform "post-compromise" techniques that previously required deep technical expertise.

The Erosion of Traditional Risk Assessment

Traditional security signals—such as the number of techniques employed or the specific interface used (e.g., Claude Code, API, or chat)—no longer accurately correlate with an actor's risk level.

  • Technique Volume: There is little correlation between skill and technique count; the least-skilled actors in the dataset used an average of 16 distinct techniques, while the most skilled used approximately 20.
  • Interface Independence: The platform used to interact with the AI does not correlate with the actor's risk level.
  • The New Differentiator: High-risk actors are distinguished by their ability to build "scaffolding" around the model, creating architectures that allow AI to chain together discrete attack stages and execute them with minimal human input.

Limitations of the MITRE ATT&CK Framework

Anthropic found that the MITRE ATT&CK framework does not currently capture the agentic orchestration and autonomous decision-making that make AI-enabled attackers particularly dangerous.

As an example, a state-sponsored espionage operation disrupted in November 2025 involved a malicious actor using Claude Code as an autonomous agent to execute commands, exploit vulnerabilities, and steal credentials. While this attack used 30 techniques across 13 tactics—comparable to medium-risk actors—Anthropic's internal risk-scoring methodology assigned it a maximum risk score of 100 due to its autonomy.

Defensive Responses and Future Frameworks

Anthropic is using these findings to develop cyber safeguards in its most capable models to block activities such as mass data exfiltration and malware development. Additionally, the lab is collaborating with MITRE to evolve the ATT&CK framework to better incorporate AI-enabled behaviors. These efforts are part of a broader commitment to sharing findings from Project Glasswing and other cybersecurity initiatives to ensure defenders maintain an advantage over evolving AI-enabled threats.

Sources

Related