Sophisticated Attacks No Longer Require Sophisticated Attackers

Anthropic published its latest threat intelligence report on September 10, covering malicious use of Claude that its team detected and disrupted between December 2025 and August 2026. If you read one security document this quarter, make it this one. Not because it describes attacks you’ve never seen before, but because it describes attacks you have seen before, running at speeds and volumes that most small and mid-sized organizations are not built to absorb.

The line that should get your attention is one of the report’s own section headings: “Sophisticated attacks no longer require sophisticated attackers.”

What the report actually found

Anthropic documented several separate groups — suspected state-sponsored operators, financially motivated criminals, and politically motivated individuals — that had no connection to one another but converged on the same playbook.

A Russian state-nexus espionage actor built AI workflows that watched their own malware for detection. When a security product flagged an implant, agents rebuilt and modified it automatically, iterating until it went undetected again. That inverts a dynamic defenders have relied on for two decades: writing a detection used to impose real cost on an adversary. Now the adversary closes that loop faster than most teams can publish the signature.

A cluster of financially motivated operators moved at machine speed. One breach of an enterprise software company went from first access to bulk data theft in hours. Another escalated from one stolen developer token to full administrative control of a cloud environment in roughly three hours. In a supply chain case, operators dumped more than 2,100 Azure AD token sets spanning over 40 corporate tenants in about 34 hours, with AI agents performing nearly all of the work.

A Chinese-speaking group ran what amounts to an automated exploit factory. One workflow iterating continuously against network appliances produced more than a dozen possible zero-day findings in a single month.

And a single individual — one person — gained internal access to at least 14 of 42 target organizations, built a custom exploit for a previously undocumented WordPress flaw, and poisoned the victim’s backups so that restoring from them would reinfect the environment.

The techniques are old. The economics are new.

This is the part worth sitting with. Anthropic is explicit that none of these operations depended on an entirely novel technique defenders have never seen: the attacks involved stolen credentials, unpatched edge devices, exposed services, SQL injection, and phishing. What changed is the labor cost. The reconnaissance, tool development, exploitation, and data sorting that used to separate a well-funded state program from a lone operator can now be delegated to models running in parallel, around the clock.

The practical consequence for a Colorado Springs manufacturer or a Denver professional services firm is this: you are no longer too small to be worth an attacker’s time. Anthropic’s assessment is that security through obscurity is finished — anything connected to the internet is a candidate for exploitation. Marginal targets just became viable ones.

Your AI accounts are now part of your attack surface

One finding deserves its own section, because most organizations haven’t thought about it yet.

Attackers are stealing AI API keys and session tokens deliberately, and the keys give them three things at once: resale value, attack compute billed to someone else, and cover, since the activity looks like it belongs to the legitimate owner. Keys were harvested from code repositories, container images, mobile app binaries, and client-side code at industrial scale — in one case, 1.8 million Android APKs were downloaded and decompiled looking for hardcoded secrets. Anthropic’s guidance is direct: treat AI keys and agent integrations with the same seriousness as production credentials, and buy AI access only through authorized channels.

If your developers have wired an AI assistant into a workflow, or your SaaS vendors have, that integration is now in scope for your security program whether or not anyone wrote it down.

What we’d tell a client to do about it

None of this calls for panic, and it doesn’t call for a new product category. It calls for shortening your cycles and closing the gaps you already know about.

Know your external footprint before the scanners do. Every one of these campaigns started with exposed infrastructure, leaked credentials, or an unpatched edge device. Our free External Cyber Exposure Review takes a domain and shows you what an opportunistic attacker sees — internet-facing assets, open services, and leaked credential indicators — with no agents to install.

Move from annual testing to a continuous rhythm. An annual penetration test remains valuable for depth, and we’d still recommend one. But a once-a-year snapshot cannot keep pace with adversaries who find and weaponize exposures in days. Pairing a manual test with quarterly automated perimeter testing closes most of that gap at a fraction of the cost.

Audit your secrets, including AI credentials. Keys in repositories, hardcoded tokens in mobile builds, and API keys in container images are the entry point in case after case. Add your AI provider keys to the same rotation and monitoring you apply to production credentials.

Assume static detection isn’t enough on its own. If adversaries can automatically rebuild malware until it evades your endpoint tool, you need behavior-based detection with humans reviewing what the automation flags. That’s the design principle behind our managed detection and response service.

Test your restores, not just your backups. Backup poisoning means a clean-looking backup isn’t proof of anything. Restore something, on a schedule, and verify it.

Tighten identity. Device code phishing and token theft featured heavily in the espionage cases. Conditional access policies, token lifetime settings, and device registration controls are governance work — exactly what a fractional CISO engagement is for.

The human part still matters

There’s an easy misread of this report: if AI finds vulnerabilities this well, why pay people to test?

Because automated discovery produces volume, not judgment. It doesn’t know which of your systems holds the data that would end your business, it doesn’t chain three medium-severity findings into one critical path the way a human operator does, and it doesn’t tell you which of the 200 findings to fix on Monday. The report’s own evidence supports this — several of the most serious compromises came from operations where a human directed every step. Attackers kept humans in the loop for the decisions that mattered. So should defenders.

Our testing is manual, U.S.-based, and fixed-price. We use automation where automation is better and people where people are better, and we’re happy to show you exactly where that line falls in our methodology.

If you’d like a straight answer about where your organization stands against this kind of activity, get in touch. We’ll start with a free External Cyber Exposure Review and a conversation — no obligation, no pressure.

Terry Bradley, CISSP is President and Founder of Mile High Cyber, serving Denver, Colorado Springs, and organizations across Colorado. He spent nearly 30 years in cybersecurity with the NSA, U.S. Air Force cyber operations, and U.S. Cyber Command.

Next
Next

You Have MFA Enabled. Have You Tested Whether It Actually Stops an Attacker?