Anthropic report warns AI lowers barriers to cyberattacks, expanding pool of targets

Anthropic's latest threat report finds that AI agents are enabling attackers to breach systems with less expertise, making a wider range of companies viable targets. In one case, an attacker used stolen credentials to take control of a cloud environment in three hours, and another breach extracted data from 200 customers of a software provider. The report suggests that as AI reduces the cost of attacks, more businesses may face intrusions.
The report documents how AI agents now handle the technical heavy lifting of intrusions, from reconnaissance to exploit development. One intrusion involved extracting more than 2,100 Azure AD authentication tokens across over 40 corporate cloud environments in roughly 34 hours. A separate campaign linked to Russian espionage used AI to continuously modify malware whenever security products flagged it, iterating until detection failed.
Anthropic's findings also show AI enabling fraud at scale. A China-based app studio operated more than 4,700 personas across dating apps, conversing with at least 25,000 people over two weeks, with gig workers handling live video calls to maintain authenticity. The report spans December 2025 through August 2026, covering surveillance, fraud, influence operations, and weapons development alongside cyberattacks.
The report suggests AI is democratizing offensive cyber capability, meaning small and mid-sized businesses—previously overlooked for their limited value—may now face intrusion attempts once reserved for major corporations. As attack costs fall, the calculus shifts: companies with modest data holdings become rational targets. This could strain under-resourced security teams and force broader adoption of defensive AI, potentially widening the gap between organizations that can afford protection and those that cannot.