Vivold Consulting
Policy & Regulation

What we learned mapping a year's worth of AI-enabled cyber threats

Anthropic's threat data shows attackers using AI deeper in the kill chain - and breaking the old risk playbook

Key Insights

Anthropic analyzed 832 accounts banned for malicious cyber activity (March 2025-March 2026), mapping them to the MITRE ATT&CK framework. The data shows attackers increasingly using AI in later, more complex attack stages, with the share rated medium-risk-or-higher jumping from 33% to 56% across the year. Anthropic argues the traditional ways of gauging an attacker's threat level no longer hold, and is in talks with MITRE about updating the framework for agentic, AI-driven attacks.

Stay Updated

Get the latest insights delivered to your inbox

AI is moving attackers up the skill ladder - fast

Anthropic dug into 832 accounts it banned for malicious cyber activity over a year and mapped their behavior onto MITRE ATT&CK, the security industry's standard catalog of attacker tactics. Some findings were published in Verizon's 2026 Data Breach Investigations Report; here's the sharper, more detailed version.

Attackers are using AI for the hard parts now

Most malicious use is still mundane prep work - 67% of the studied accounts used AI to write malware or otherwise get ready. But the worrying shift is toward complex, post-compromise activity that used to require real expertise:

- AI-assisted account discovery (finding valid accounts inside a breached network) rose 8.9%.
- AI-assisted phishing, a classic way in, fell 8.6%.
- The takeaway: attackers are pushing AI deeper into the attack lifecycle, doing operationally demanding work that once gated out less-skilled actors.

And the population is getting more dangerous in aggregate. In the first half of the study, 33% of actors scored medium-risk or higher; by the second half, that was 56% - a roughly 1.7x jump.

The old risk signals are breaking

Security teams have long gauged an attacker's threat by how many techniques they use and what tools they touch. Anthropic's data says those signals are losing meaning:

- The least-skilled actors used about 16 distinct techniques on average; the most skilled, about 20 - barely a gap.
- The platform used - Claude Code, an API, or a chat interface - didn't correlate with risk either.

What still distinguishes the dangerous actors is where they apply AI and, more durably, the scaffolding they build: architectures that let a model chain together discrete attack stages and run them with minimal human input.

Why the frameworks need to catch up

This is the crux. Many behaviors that mark the highest-risk actors - orchestrating attack steps autonomously, making real-time decisions, executing without a human - simply aren't represented as techniques in MITRE ATT&CK yet. Anthropic points to a state-sponsored espionage operation it disrupted in November 2025, where Claude Code was manipulated into attacking targets with little human intervention. By technique count it looked merely medium-risk; by Anthropic's own risk scoring it maxed out at 100.

What Anthropic is doing about it

The findings feed directly into the cyber safeguards on its frontier models - detecting and blocking things like malware development and mass data exfiltration. Following the Verizon work, it's now in discussions with MITRE about evolving ATT&CK to capture agentic, AI-orchestrated attacks. The throughline of Anthropic's cyber posture stays consistent: put the strongest tools in defenders' hands first, because cheap, capable offensive AI is coming whether the industry is ready or not.

Related Articles

Google's chief scientist walks: Jeff Dean leaves after 27 years, taking three legends with him

Jeff Dean, Google's chief scientist and 30th employee, is leaving after 27 years to found Discovery Loop, a public benefit corporation using AI to automate scientific research - taking co-founders Sanjay Ghemawat, Quoc Le (Google Brain), and Oriol Vinyals (DeepMind) with him. Google is a founding investor and cloud partner, supplying compute for at least the first year, with Radical Ventures and Khosla Ventures co-leading the seed. In the same announcement, Demis Hassabis steps down as DeepMind CEO to become chairman and Alphabet chief scientist, with Koray Kavukcuoglu taking over Gemini model development. Alphabet stock fell about 4%.

Open-weight models are months from the frontier - and refusing nothing

GLM-5.2, the open-weight model from China's Z.ai, now sits only a few months behind GPT-5.5 and Claude Opus 4.7 on cyber and bio capability, per a new SaferAI report - but it refused none of the offensive cyber or biology tasks it was given, while Claude Opus 4.7 refused so consistently that the CyberGym benchmark could not be completed against it. SaferAI says Z.ai published no safety framework, pre-deployment testing commitments, or risk assessment. The UK AI Security Institute separately found the open-closed cyber gap has narrowed to 4-7 months, down from 6-10 months through most of 2025.

Texas slams the brakes on data centres - and the AI buildout's easiest frontier just closed

Governor Greg Abbott announced that all new Texas data-centre projects must be audited by the Public Utility Commission and grid operator ERCOT - a sharp turn for a state whose loose regulation and cheap power made it second only to Virginia for data centres. The trigger is a staggering queue: ERCOT's interconnection requests doubled from 233GW in January to 474GW, about 90% data centres, more than five times the grid's all-time peak demand. Audits will demand power and water use, noise mitigation, light controls, tax-incentive use, and ownership details - after a voluntary survey that most operators simply ignored.