For a while, 'AI-assisted attack' was a phrase that got used loosely, more a talking point than a description of anything real. That has changed. On 10 September 2026, Anthropic published its most detailed account yet of its AI tool being used in real cyber operations, covering investigations it ran between December 2025 and August 2026. It is worth looking at what those cases were, plainly, and what they mean for how you defend a business.
The useful thing about this reporting is that it is not speculation. These are operations that were detected, investigated, and shut down, with enough detail to understand what actually happened. And one line from the report captures the whole shift better than anything we could write: sophisticated attacks no longer require sophisticated attackers.
The headline finding
The report's own conclusion is that the difference between a well-resourced state operation and a lone individual is no longer sophistication but intent. AI has closed the gap. A single person can now run the kind of multi-victim campaign that used to need a team of skilled operators.
Case one: speed
A cluster of financially motivated operators broke into companies to steal data and extort them. In one intrusion, they went from a single stolen developer token to full administrative control of the victim's cloud environment in about three hours. In another, they exported more than 2,100 access tokens spanning over 40 corporate tenants in around 34 hours. None of that involved an exotic new technique. It was ordinary intrusion work, but run at a speed and scale that used to be out of reach for a small group, because the AI handled the reconnaissance, the movement between systems, and the bulk data processing.
Case two: scale from one person
A lone actor targeting European political organisations and their software suppliers used AI across the whole operation, building a custom scanner, finding a way in, and processing what was stolen. Of 42 organisations targeted, they got into 14, and the entire platform they built to publish the stolen data was, in the report's words, created by just one person. The operation ran for a month, in part on stolen API keys. What used to require a team and specialist skills was done by one motivated individual with the right tooling.
Case three: a new target
A newer pattern in the report is attackers going after AI credentials themselves, the API keys and tokens your business uses to run AI tools. Stolen keys give an attacker three things at once: resale value, free compute to run their own attacks, and cover, because the activity looks like it came from you. In several cases, once attackers were inside a victim's environment, the first thing they took was the AI keys, then switched their own attack workloads onto the victim's account. It is a reminder that AI keys and integrations now belong on your asset list, treated as seriously as any production credential.
What this changes, and what it does not
It is easy to read cases like these and conclude the sky is falling. It is not. The attacks themselves are familiar, stolen credentials, unpatched systems, exposed services, phishing, and the defences against them are the ones good security teams already know. What has changed is the economics. The work that used to set well-resourced attackers apart, such as reconnaissance, exploitation, and data processing, is now delegated to AI running at machine speed and in parallel. So you should expect more attacks, aimed at more targets, including smaller organisations that previously flew under the radar.
That last point is worth sitting with. Many mid-sized businesses have quietly assumed they are too small to be worth a serious attacker's time. The report is blunt about this: cheaper attacks make previously marginal targets viable, and encourage higher-volume, lower-effort operations. The assumption that you are too small was always shaky. It stops holding at all when the cost of an attack drops.
The other thing that has not changed is the way in. In nearly every case, the attacker still needed a foothold, a weak credential, an unpatched system, an exposed service, or an API key left in public code. AI made the operation that followed faster, but the entry points were the same ordinary weaknesses they have always been.
Where to focus
Because the entry points have not changed, the priorities do not either. Assume a higher volume of ordinary attacks rather than an exotic new threat, and make sure your existing controls are actually in place and working. Close the entry points first: multi-factor authentication, prompt patching, least-privilege access, and removing unused credentials remain the highest-value work. Treat AI keys as production credentials, keep them out of public code, rotate them, and monitor their use. Test how you would respond before you have to, because breaches completed in two to three hours leave far less time to react. And keep a current picture of your systems, data, and access, because you cannot protect what you have not accounted for.
Conclusion
None of this is new advice, and that is rather the point. The value of these disclosures is not that they reveal some unstoppable new weapon. It is that they show, in concrete detail, why the unglamorous fundamentals still decide who gets hurt and who does not. If you are not sure how your business would hold up against a higher volume of these attacks, or where your real entry points are, that is exactly the kind of question a short scoping conversation can answer.