{"id":619974,"date":"2026-06-04T02:29:32","date_gmt":"2026-06-04T02:29:32","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/619974\/"},"modified":"2026-06-04T02:29:32","modified_gmt":"2026-06-04T02:29:32","slug":"what-we-learned-mapping-a-years-worth-of-ai-enabled-cyber-threats-anthropic","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/619974\/","title":{"rendered":"What we learned mapping a year\u2019s worth of AI-enabled cyber threats \\ Anthropic"},"content":{"rendered":"<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">As AI transforms the nature of and methods behind cyberattacks, how well do the techniques and frameworks used by the security community hold up?<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In a new report, we seek to answer that question. We examine 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026 and map them onto <a href=\"https:\/\/attack.mitre.org\/\" rel=\"nofollow noopener\" target=\"_blank\">MITRE ATT&amp;CK<\/a>, a longstanding database of the tactics and techniques used by cyberattackers. We published some of these results in Verizon\u2019s <a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/\" rel=\"nofollow noopener\" target=\"_blank\">2026 Data Breach Investigations Report<\/a> (DBIR), and are sharing a more detailed analysis here. These 832 cases are just a subset of the total number of accounts banned during this period, but they represent those where we had enough detail to conduct a thorough assessment of the attackers\u2019 techniques.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">There were three main conclusions from our analysis:<\/p>\n<p>Malicious actors are using AI in ways that make them more dangerous. More specifically, threat actors are using AI in the later, more complex stages of their cyber operations.Cyberattacks are becoming more autonomous, and the fact that AI can be used to chain together many parts of the attack means that the old ways of differentiating high- from low-risk actors are no longer as effective.The MITRE ATT&amp;CK framework does not fully capture the tools and activities that make AI-enabled attackers so dangerous.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Below we provide a summary of each of these conclusions. You can read a longer analysis on our <a href=\"https:\/\/red.anthropic.com\/2026\/attack-navigator\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Frontier Red Team blog<\/a>.<\/p>\n<p>How AI makes attackers more dangerous<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The most common AI-enabled activities in our database related to preparing for a cyberattack, such as writing malware (560 of the 832 accounts we studied, or 67.3%, used AI for this purpose). A smaller number of actors use AI for more complex activities\u2014for example, 54 of the 832 actors (6.5%) used AI to assist with \u201clateral movement,\u201d which involves navigating deep inside a compromised network.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">We found evidence consistent with AI being used to help increase the threat level of attackers. In the first six-month period of our analysis, 33% of actors were classified by our risk-scoring system as medium risk or higher. But by the second six-month period, that share had jumped to 56%\u2014a roughly 1.7-fold increase.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Across the period we studied, attackers\u2019 use of AI shifted from techniques to gain initial access to a system towards activity carried out once they were inside the system. For example, the use of AI for account discovery\u2014identifying valid accounts inside a compromised environment\u2014rose 8.9%, while AI-assisted phishing\u2014a common technique to gain access to a system\u2014fell 8.6%. This suggests that attackers are increasingly applying AI deeper in the attack life cycle.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">These sorts of \u201cpost-compromise\u201d techniques used to be restricted to actors with the technical knowledge to carry them out. Our investigation shows that AI can now be made to perform these activities on behalf of less sophisticated actors.<\/p>\n<p>Why it\u2019s harder to assess an actor\u2019s threat level<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">How do security teams assess the risk level of a cyberattacker? Traditionally, they\u2019ve used information like how many different techniques they employ and what tools or interfaces they use. But our analysis suggests that these signals no longer paint an accurate picture of the risk level of a given threat actor.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Now that AI can perform highly technical tasks on an actor\u2019s behalf, there\u2019s little correlation between the skill of a threat actor and how many techniques they use: the least-skilled actors in our dataset used about 16 distinct techniques on average, whereas the most skilled used about 20. Likewise, the specific platform used\u2014Claude Code, an API, or a chat interface\u2014also did not correlate with an actor\u2019s risk level.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">What often helps distinguish higher-risk actors is where in the attack life cycle they apply AI. For example, they concentrate their use of AI on more operationally demanding techniques\u2014those that require significant time, oversight, or real-time decision making to carry out\u2014like account discovery, lateral movement, and privilege escalation, rather than just on tasks that allow them to gain initial access to the system.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">But even that signal is already eroding: as discussed in the previous section, those operational techniques are exactly where the broader population is heading as more actors get classified as higher risk. The more durable differentiator is the type of scaffolding attackers build around the model: higher-risk actors design architectures that allow models to chain together discrete stages of a cyberattack and carry them out with minimal human input.<\/p>\n<p>Why security frameworks need to change<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Many of the behaviors that distinguish the highest-risk actors\u2014such as the use of AI to orchestrate steps in the attack chain sequentially, make real-time decisions about what to do next, and execute without human intervention\u2014are not yet included as attacker techniques in the MITRE ATT&amp;CK framework.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Consider the state-sponsored cyber espionage operation we <a href=\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\" rel=\"nofollow noopener\" target=\"_blank\">disrupted in November 2025<\/a>. In that case, a malicious actor manipulated Claude Code into attempting to infiltrate targets around the world, with little human intervention. Mapping it against the MITRE ATT&amp;CK framework shows that the actor used 30 techniques across 13 tactics, which was comparable to many medium-risk actors in our dataset. Clearly, focusing on the number of techniques this actor used underplays how dangerous they really were (by contrast, applying our risk-scoring methodology to this attack earns it the maximum risk score of 100).<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In that attack, the model worked as an autonomous agent: it executed commands, exploited vulnerabilities, stole credentials, and made tactical decisions, only requiring human input at a few key moments. There is no ATT&amp;CK ID for this type of agentic orchestration\u2014yet these are precisely the behaviors we expect to see much more of as AI agents become more capable.<\/p>\n<p>Looking ahead<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">The findings from this analysis helped inform the safeguards we build into our models. For example, we\u2019ve developed and deployed cyber safeguards on our most capable models to detect and block some of the activities uncovered here, like developing malware or mass data exfiltration. Following on from our work with Verizon, we\u2019re also in discussions with MITRE about how the ATT&amp;CK framework might evolve to include the AI-enabled behaviors we observed.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">Frontier models are rapidly changing the tools both attackers and defenders have at their disposal. We are committed to helping defenders get ahead of these evolving tactics, and to putting the most powerful tools in the hands of defenders first. We\u2019ll continue to share what we learn from <a href=\"https:\/\/www.anthropic.com\/glasswing\" rel=\"nofollow noopener\" target=\"_blank\">Project Glasswing<\/a>, from datasets like the one we gathered here, and from our other cybersecurity activities.<\/p>\n<p class=\"Body-module-scss-module__z40yvW__reading-column body-2 serif post-text\">In our <a href=\"https:\/\/red.anthropic.com\/2026\/attack-navigator\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Red blog post<\/a>, we share an interactive visualization of the techniques used by attackers, in order to help defenders stay ahead of AI-enabled threats. <\/p>\n","protected":false},"excerpt":{"rendered":"As AI transforms the nature of and methods behind cyberattacks, how well do the techniques and frameworks used&hellip;\n","protected":false},"author":2,"featured_media":619975,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-619974","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/619974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=619974"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/619974\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/619975"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=619974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=619974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=619974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}