AI could make more companies worth hacking, Anthropic report suggests
As AI reduces the amount of expertise needed to conduct cyberattacks, it is widening the number of companies that might make tempting targets.
That’s one implication of a number of findings from Anthropic’s most recent Threat Intelligence report published earlier this month.
The report provided plenty of examples of the way powerful AI models are making cyberattacks almost trivially easy.
In the past, the effort required to pull off a successful attack often meant that sophisticated hackers would choose to go after high-value targets.
As the old saying goes, “why do robbers rob banks? Because that’s where the money is.” But the rise of AI agents with genius-level cyber skills, all available at the push of a button, means that there is little cost in time and human effort to go after less obvious targets.
Anthropic says this may mean many more companies will be attacked.
The company said it had found attackers using Claude to navigate corporate systems they barely understood, identify valuable data and write code to exploit vulnerabilities, the report said.
In one case, an attacker with a stolen developer token took full administrative control of a company’s cloud environment in roughly three hours, the report said.
A separate intrusion shows how far that work can carry an attacker.
After breaching a software provider, attackers Anthropic described as suspected affiliates of “ShinyHunters” (which also recently claimed credit for a major data breach against the FBI) extracted data belonging to roughly 200 of its customers.
Anthropic said AI agents performed nearly all the work.
The 154-page report covers activity Anthropic disrupted from December 2025 through August 2026.
Alongside cyberattacks, it examines government surveillance, fraud, influence operations, weapons development, biological research, and unauthorized model distillation.
From stolen credentials to stolen data During the software-provider intrusion, attackers extracted more than 2,100 sets of Azure AD authentication tokens across more than 40 corporate cloud environments, in about 34 hours.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on fortune.com — the content belongs to Fortune.