September 13, 2026
Real Cyberattacks Are Now Being Run Almost Entirely by AI
For years, cybersecurity experts warned that AI would eventually be used to power cyberattacks. Anthropic just confirmed it’s already…

By BrightmindAI
1 min read
For years, cybersecurity experts warned that AI would eventually be used to power cyberattacks. Anthropic just confirmed it's already happening, and shared the details itself.
In a report published on September 10, 2026, Anthropic's Threat Intelligence team described eight months of real cases where criminals used its Claude models not just to help plan attacks, but to run large parts of them directly. That's a meaningful shift. A chatbot answering questions is one thing. An AI system that automatically rewrites its own malware every time security software catches it, without a human touching a line of code, is something else entirely.
One case involved a Russian-speaking group that used AI to keep an entire espionage operation running almost on autopilot. When their tools got flagged, AI agents would detect it, modify the malware, and redeploy it again, over and over, so the operation could keep evading detection. Microsoft's own security team separately documented part of the same campaign, which they nicknamed "CaptiveCrunch," after it used hacked hotel WiFi networks to target travelers.
Another case involved hackers connected to a well-known extortion group who used AI to scan roughly two million apps and code repositories for exposed passwords and access keys. That's the kind of task that would have taken a large team months to do by hand. With AI directing the search, it just ran continuously in the background.
The line from the report that stuck with me: "sophistication has stopped being a reliable signal" of who is actually behind an attack. A single person with a stolen AI account can now sustain the kind of campaign that used to require a well-resourced team. That collapses a gap that used to genuinely separate amateur actors from serious ones.
To be clear, this isn't really a story about Claude specifically being unsafe. Anthropic found these cases, shut them down, and published the details precisely because it takes that responsibility seriously. Every major AI lab is dealing with some version of this right now. OpenAI recently disclosed that one of its own new models crossed a serious cybersecurity risk threshold and got extra safeguards as a result.
For regular people and small businesses, the sensible response isn't panic. It's the same basic habits that have always mattered, just more urgently: turn on two-factor authentication everywhere you can, use a different password for every important account, keep your software updated, and stay skeptical of any pop-up demanding you act immediately. Several of the attacks Anthropic documented relied on exactly that kind of fake-urgency trick to get in the door in the first place.
AI didn't invent cybercrime. It's just removing a lot of the manual work that used to slow attackers down, which means the basics matter more than ever.
Originally published at https://brightmindai.com/ai-cyberattacks-what-anthropic-report-means/