This chapter discusses how AI changes the speed and scale of cyberattacks rather than inventing entirely new techniques. This site splits it into 6 case units.
p. 4–40 · 8 case units
Key findings
Capability gains are mainly in speed, scale, and depth; entry points are still commonly credentials, unpatched systems, and social engineering.
GTG-50020 must be read with its negative evidence: no unreleased models were obtained, and Anthropic's own systems were not breached.
Fake resellers turn AI access itself into stolen goods: what users buy may not be Claude, and their login state may be harvested from their device.
What happened
Original report pages 4–40. It opens by discussing the spectrum from assistance to orchestration, then presents GTG-20006 (espionage), GTG-50014 (opportunistic theft and ransom), GTG-10007 (automation frameworks), and within the supply chain section GTG-50021 (fake resellers), GTG-50020 (intrusion from a hotel system toward an AI company), and GTG-50029 (European politically motivated organizations).
Appendix A belongs to this chapter and is not an eighth category of misuse. Public interpretation should not turn the indicator list in the appendix into a searchable attack catalog.
Reading suggestion: look at each case's 'what we still don't know' before the numbers. Being scanned, being targeted, and being successfully breached are three different things.
Original report illustration: opening overview of the cyber operations chapter. Text in the figure is the original English.
According to an Anthropic report, a group of Chinese-speaking operators assessed to be likely based in Changsha, Hunan, China, used Claude as the engineering and orchestration layer for a coordinated attack campaign. Multiple workflows ran in parallel: intrusions into production systems, reconnaissance of foreign government networks, ongoing vulnerability research and exploit development against mainstream endpoint security products, malware development, and operation of an unattended intelligence-collection platform. The targets were roughly 50 organizations. Attribution information such as the operators' location comes from the report's assessment; their vulnerability findings were validated only in the actors' own experimental environments.
According to Anthropic's September 2026 report, GTG-20006 is a cyber espionage actor who uses AI to automate operations and gain speed. Anthropic says its attribution is consistent with public reporting linking the actor to Midnight Blizzard. The actor used a custom toolkit including two types of Windows implants, a mobile exploitation suite, a credential stealer targeting browser password vaults, a phishing platform designed to impersonate priority targets such as government organizations, and a management console for controlling compromised accounts. The report observed that GTG-20006 automated most of its operations — from development, infrastructure acquisition, phishing, command-and-control persistence, to data exfiltration — through customized AI-driven workflows.
According to the report, an Iran-linked threat actor used Claude to collect and analyze publicly available data to develop targeting recommendations against U.S. Navy forces in the region. The actor used Claude to write targeting handbooks, identifying and tracking naval positions based on open-source information. The same account also developed enterprise software for Iranian state systems, including designing a large-scale domestic surveillance platform combining automatic license plate recognition and mobile device identifier interception. This page does not publish any target coordinates or exploitation details.
According to the report, an Iranian threat actor used 16 free Claude.ai accounts across 16 single-operator organizations to develop malware, delivery pipelines, and phishing portals targeting domestic Iranian users. The delivery pages were designed to serve malicious content only to visitors with IP addresses from Iran, themed around censorship-circumvention tools and fabricated Persian-language news brands. The actor used Claude to develop the SECOMS64 modular Windows implant, including a keylogger, screenshot capture, Chrome credential extraction, and more. This page does not publish any malware code or phishing links.
According to Anthropic's report, multiple opportunistic intrusion clusters suspected of being linked to the ShinyHunters group used AI to enhance their criminal activity. These actors broadly scanned unpatched internet-facing systems, rummaged through public containers, code repositories, mobile apps, and more for credentials, tokens, and API keys, then went straight for databases to steal customer data after gaining access, and extorted victims by threatening to publish or sell the data. The report says AI agents did most of the work, with one case going from a stolen token to full control of a victim's cloud environment in about 3 hours. The report also makes clear: Anthropic's own systems were not breached by this actor.
According to Anthropic's report, GTG-50020 is a Russian-speaking, financially motivated actor that historically targeted hotel booking and fintech platforms. In one intrusion, they exfiltrated about 26 GB of data from a victim and attempted to obtain $1.5 to $2.5 million through ransom (or by selling the data on dark web forums). They then pivoted the same techniques toward the AI industry: by injecting malicious instructions into an AI vendor's automated evaluation sandbox, they made the sandbox hand over the credentials it held—including production AI API keys for multiple providers held by that vendor. The report makes clear: the actor never obtained access to unreleased Claude models, and Anthropic's own systems were not breached.
According to Anthropic's report, the AI supply chain has become a target, loot, and source of attack compute for malicious actors. AI access in the form of stolen API keys, session tokens, and devices is increasingly the sole objective of multiple criminal groups. GTG-50021 is a fake AI reseller service operated by a Russian- and Ukrainian-speaking actor. Customers thought they were buying discounted Claude access, but their traffic was silently routed to other models; the reseller tool also installed a credential collector on the device, reselling account credentials to other proxy networks.
According to Anthropic's report, in spring 2026 a French-speaking actor used Claude to target European political parties, media, think tanks, and the software services they use. The report tracked 42 target entities, of which at least 14 were internally accessed, with an estimated 12 to 26 GB of data stolen. This is an example of one person using AI to scale intrusion and data correlation capabilities; this page does not provide any personally identifiable data.
Limits of response
The cases in this chapter were selected for disclosure by the publisher and cannot be used to derive global incidence rates or country rankings.
Specific exploitation steps, prompts, and concrete IOC values are not included in this site's text.