Innovation & Tech

AI Is Making More Companies Worth Hacking, Anthropic Warns

Anthropic's 154-page threat report details attackers using Claude to seize cloud admin control in three hours and steal tokens across 40 corporate environments.

By Amara Osei

3 min read

Updated

AI could make more companies worth hacking, Anthropic report suggests
AI could make more companies worth hacking, Anthropic report suggestsschoschie / Openverse

What's News

  • An attacker used Claude to gain full administrative control of a company's cloud environment in roughly three hours, according to Anthropic's Threat Intelligence report covering December 2025 through August 2026.
  • Suspected ShinyHunters affiliates extracted more than 2,100 Azure AD authentication tokens across 40+ corporate cloud environments in about 34 hours, stealing data belonging to roughly 200 customers of a software provider.
  • A China-based app studio used Claude to run more than 4,700 dating-app personas, conversing with at least 25,000 people over two weeks in April.

An attacker with a stolen developer token took full administrative control of a company's cloud environment in roughly three hours, using Claude to navigate systems the intruder barely understood. That case sits at the center of Anthropic's most recent Threat Intelligence report, published earlier this month, and it points to a structural shift in the economics of cybercrime.

The 154-page report covers activity Anthropic disrupted from December 2025 through August 2026. Alongside cyberattacks, it examines government surveillance, fraud, influence operations, weapons development, biological research, and unauthorized model distillation.

Anthropic's core argument is about target selection. In the past, the effort required to pull off a successful attack meant sophisticated hackers concentrated on high-value targets — the digital equivalent of robbing banks because that's where the money is. AI agents with genius-level cyber skills, available at the push of a button, remove the time and human effort that once made smaller targets unattractive. Many more companies will likely be attacked as a result, Anthropic says.

The report backs that claim with specifics. In one intrusion, attackers breached a software provider and extracted data belonging to roughly 200 of its customers. Anthropic described the attackers as suspected affiliates of "ShinyHunters," the group that recently claimed credit for a major data breach against the FBI. AI agents performed nearly all of the work.

From stolen credentials to stolen data

During that software-provider intrusion, the attackers pulled more than 2,100 sets of Azure AD authentication tokens across more than 40 corporate cloud environments in about 34 hours. Such tokens let attackers access cloud services as legitimate users without ever knowing a password.

The hackers supplied broad objectives and let Claude write and run scripts. When an approach failed, they instructed Claude to keep trying other tactics until one succeeded. Anthropic calls this "vibe hacking." The company first described the technique in a suspected state-backed campaign last November; it now appears across every type of cyber attacker Anthropic investigated. Attackers can download software that coordinates AI agents through different stages of an intrusion, the company said.

The pattern scales. Anthropic reported that a Russian-speaking attacker with a history of targeting hotel-booking and financial-technology platforms stole roughly 26 GB of data from one victim and sought $1.5 million to $2.5 million through extortion or dark-web sales. The report describes the actor deploying parallel AI agents to investigate targets and test ways in. A later campaign from the same infrastructure targeted roughly 30 AI companies in about four days.

State-linked operations use the same tooling with more discipline. In a campaign Anthropic connected to Russian espionage, agents monitored whether security products detected the operators' malware. When malware was flagged, the agents modified and rebuilt it in a workflow designed to keep iterating until it could evade the security software.

Scammers are also supercharged

The same economics apply to fraud. A China-based app studio used Claude to operate more than 4,700 personas across a network of dating apps, conversing with at least 25,000 people over two weeks in April. Real gig workers handled live video calls and social-media follows — the tasks that persuaded users the service was authentic. Users paid for messaging and matching through in-app coins.

That ability to catfish people at unprecedented scale shows how con artists no longer need to be selective about victims, since the marginal cost of running a highly individualized scam has collapsed.

For corporate security teams, the implication is direct: if AI has cut the cost of an attack toward zero, the threshold for being a worthwhile target has dropped with it. Companies that once relied on being too small to bother hacking no longer have that protection.

Original: anthropic.com

Share this article:

More from Amara Osei

Amara Osei

Show full bio

Senior reporter covering consumer brands and retail at Business Bearings.

230 articles

Related articles

« Previous articleNext article »