AI Agents Are Handling More of the Work
Earlier uses of generative AI in cybercrime often involved discrete tasks: drafting a convincing email, explaining malicious code, translating material or researching a potential target.
Agentic systems can go further.
According to Anthropic, attackers have used AI for reconnaissance, vulnerability identification, exploitation and data theft. In some cases, multiple agents were assigned different jobs within a broader operation.
That does not amount to an AI system independently deciding whom to attack. The operations described by Anthropic remained under human control.
What is changing is how much work can happen between the operator's instructions.
An attacker who can automate research, technical analysis and repetitive steps can potentially pursue more targets without increasing the size of the human team behind the operation. The security risk therefore comes as much from scale and efficiency as from any entirely new hacking technique.
Anthropic Links Claude Use to Russia-Connected Espionage
One case examined by Anthropic involved what the company assessed to be Russia-linked cyber activity targeting Ukrainian officials.
Anthropic said Claude was used during an espionage campaign that included phishing and other operational tasks. Reporting on the findings has linked some of the activity to Midnight Blizzard, a Russian hacking group known to Western cybersecurity researchers.
Cyber attribution is rarely straightforward. Anthropic's account reflects its own investigation into activity on its systems, and not every detail of the operation can be independently confirmed.
Even so, the case offers a useful example of how AI can be incorporated into established intelligence methods.
Phishing, reconnaissance and credential theft existed long before modern generative models. AI does not need to invent a new form of espionage to be useful to an intelligence operation. Making existing techniques faster, cheaper or easier to scale can be valuable on its own.
Surveillance Operations Targeted Journalists and Dissidents
Anthropic also said it found accounts connected to government-linked actors in Mali, China and Iran using Claude to support surveillance work.
According to the company's investigation, AI helped process information and identify potential targets, including journalists, activists, dissidents and politicians.
Anthropic subsequently banned accounts associated with the activity.
The surveillance cases point to a different consequence of AI adoption from automated hacking. Large amounts of collected information have traditionally required people to sort, translate and analyse them. Language models can reduce some of that workload.
Jacob Klein, Anthropic's head of threat intelligence, has argued that the effect may be to make established surveillance practices cheaper and more efficient rather than fundamentally changing whom governments want to monitor.
That distinction is important. AI may alter the economics of surveillance before it changes its underlying purpose.
The Most Advanced Model Is Not Always Necessary
The cases Anthropic examined also challenge the assumption that preventing misuse is mainly a matter of restricting access to the industry's most capable models.
The company found malicious activity involving models across its Claude product range, including Haiku, Sonnet and Opus.
Many tasks useful to attackers do not require frontier-level reasoning. Sorting information, generating phishing material, conducting research or assisting with reconnaissance can still have operational value when performed by less powerful models.
For AI companies, that broadens the safety problem.
Security controls cannot focus solely on a small group of flagship models if cheaper and more widely available systems are already capable of performing tasks that malicious operators find useful.
Anthropic Reports Biological and Weapons-Related Misuse
The company's findings were not limited to conventional cybersecurity.
Anthropic said it disrupted five cases involving scientists who attempted to use Claude in connection with biological-weapons-related research.
One case, according to reporting on the company's findings, involved work related to adapting avian influenza.
Anthropic also identified actors associated with Russia, China and Yemen using AI in connection with conventional weapons development and related software.
These findings require particular caution. They are based on Anthropic's detection and interpretation of activity on its platform, and the company has not provided enough public information for all aspects of the cases to be independently reconstructed.
Still, they illustrate why AI safety policies increasingly extend beyond preventing models from producing obviously malicious computer code. Scientific and engineering assistance can create different risks when sufficiently detailed information is combined with specialist knowledge.
Providers Face a Difficult Line Between Defence and Abuse
Cybersecurity presents AI companies with an unusually complicated enforcement problem because many of the same technical capabilities have legitimate uses.
A security researcher may ask a model to identify vulnerabilities because they want to fix them. An attacker can ask a similar question because they want to exploit them.
The same overlap exists in malware analysis, network reconnaissance and code debugging.
That makes user intent, patterns of behaviour and the broader context of an account important to detecting abuse. A single technical prompt may reveal relatively little about whether the person behind it is protecting a system or preparing to compromise one.
Anthropic said it shut down accounts associated with the operations covered in its report and used the cases to improve its safeguards.
The cycle is likely to continue: providers introduce more capable systems, legitimate users find new applications for them, malicious actors test the same capabilities, and security teams adjust their controls in response.
Autonomy Changes the Cybersecurity Calculation
The larger issue raised by Anthropic's report is not a future in which AI spontaneously decides to become a hacker.
The more immediate concern is considerably less speculative.
Human attackers can increasingly delegate work to software that can research a target, interpret results, select intermediate actions and continue towards an objective without requiring instructions at every stage.
Even partial autonomy matters if it allows one operator to supervise work that previously required several people or many hours of manual effort.
That creates a scaling problem for defenders. Cyberattacks do not have to become fully autonomous to become more numerous or efficient.
Anthropic's findings suggest that this transition has already begun. The question for AI providers and cybersecurity teams is how quickly defensive systems and safeguards can adapt as agents become capable of handling longer and more complicated chains of work.






