Anthropic report shows AI-assisted attacks moving toward orchestration
Anthropic’s September threat report documents Claude-assisted cyber, influence, surveillance, fraud, weapons, and biological-misuse activity; Microsoft independently corroborates the AI-augmented device-phishing campaign behind one case.
Anthropic’s September 2026 threat report documents a shift in how attackers use AI: Claude was involved in workflows that coordinated reconnaissance, phishing, exploitation, data collection, and evasion, rather than simply answering isolated questions. Anthropic says it disrupted the activity and shared relevant intelligence with authorities and industry partners.
The report covers incidents observed from December 2025 through August 2026. It spans cyber operations, influence operations, surveillance, scams and fraud, conventional weapons development, biological misuse, and illicit model distillation. Anthropic says the cases are unusual examples selected for their novelty and severity, not a claim that ordinary Claude usage follows the same pattern.
Claude-assisted operations crossed the kill chain
Anthropic describes multi-agent workflows that carried out reconnaissance, exploitation, and exfiltration under human direction. In one Russia-linked espionage case, the company says AI-supported tooling helped automate phishing infrastructure, persistence, command-and-control activity, and data extraction against government, diplomatic, defense, and drone-supply-chain targets in Europe and elsewhere.
The report also describes opportunistic criminal campaigns that used AI to scan software, mobile applications, repositories, and exposed services for credentials and tokens. In one SaaS supply-chain compromise, Anthropic says attackers used Claude to understand APIs, create privileged tokens, and build tools for bulk exports across downstream customer environments. Anthropic says it banned associated accounts and engaged victims, authorities, and industry partners.
Microsoft independently confirms the device-phishing pattern
Microsoft’s Threat Intelligence team reported the related CaptiveCrunch campaign in July. Microsoft attributed the activity to Storm-2945, a sub-cluster of Midnight Blizzard, and observed AI-augmented device-code and OAuth phishing, traffic manipulation through hospitality networks, and malware delivery to travelers.

That corroboration supports the report’s narrower claim that AI-assisted operations are being paired with established identity and social-engineering techniques. It does not independently validate every case in Anthropic’s report, and Anthropic’s attribution remains its own assessment. Microsoft recommends treating hotel, conference, airport, and other captive-portal networks as untrusted, avoiding software updates offered through unexpected web prompts, and restricting device-code authentication where possible.
What defenders should change now
The practical lesson is operational. Review exposed API keys, session tokens, OAuth grants, CI/CD credentials, and service accounts as attack paths that can be discovered and chained quickly. Alert on unusual device registrations, device-code sign-ins, bulk mailbox or database exports, new persistence mechanisms, and repeated malware rebuilds after detection.
Anthropic’s report includes indicators of compromise and technical case studies for defenders. Microsoft’s CaptiveCrunch article adds detection and hunting guidance for Entra ID, Defender, and identity telemetry. Teams should use the original reports for the full indicator lists and product-specific actions; this article intentionally does not reproduce operational malware details.
The next milestone is whether other providers publish comparable telemetry. Anthropic’s cases show what one vendor observed and blocked; Microsoft’s independent reporting shows that the identity and captive-network techniques are already visible outside Anthropic’s service. Together, they justify tighter controls around AI-assisted workflows, cloud credentials, and device-code authentication now.
Sources and methodology
This article uses Anthropic’s September 2026 threat-intelligence report as the primary source and Microsoft Threat Intelligence’s CaptiveCrunch report as independent corroboration for the AI-augmented phishing and intrusion pattern. Both sources were checked through the LinkLoot source-fetching pipeline. The report contains technical security language that triggered an automated keyword warning; publication proceeded only after corroboration from Microsoft and with claims limited to the verified overlap.
Try the related loot
Use Cloudflare Optional OAuth Scopes for narrower app permissions
