Anthropic's Threat Report: The Most Detailed Yet

AI security risks are set out in unusual detail in Anthropic's threat intelligence report, published on 10th September. The report documents operations the company detected and shut down between December 2025 and August 2026.
It covers seven areas of harm: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and model distillation.
The actors range from suspected state-sponsored groups and commercial spyware vendors to lone individuals. Cases run from fake dating apps defrauding users to surveillance systems tracking dissidents.
Two of its findings reach directly into companies with fewer than 250 staff.

The headline finding
One sentence in the report matters more than the rest. In Anthropic's words, 'Sophisticated attacks no longer require sophisticated attackers'.
Sophistication has stopped working as a signal of who is behind an operation. A hacktivist, a financially motivated crew and a state espionage operator all ran multi-victim campaigns using the same methods.
The attacks themselves are familiar. Stolen credentials, unpatched edge devices, exposed services and phishing account for nearly all of the initial access.
What changed is the economics. Reconnaissance, tool building, exploitation and data processing used to demand skilled people and time. Those tasks now run at machine speed and in parallel.
The numbers behind it
The report records one compromise moving from a single stolen developer token to full administrative control of a cloud environment in roughly three hours. Another operator worked through more than 2,100 authentication token sets spanning over 40 corporate tenants in about 34 hours.
One espionage group targeted roughly fifty organisations across education, retail, energy, technology, healthcare, finance, manufacturing and government. Two of its operators turned out to be undergraduate students at a Chinese university.
One person working alone reached inside 14 of the 42 organisations they targeted.
AI moved from assistant to operator
The report tracks a shift in how attackers use the technology. At one end they treated Claude as an engineering assistant. Further along, they directed it to carry out operations while a human chose each target.
At the far end, operations ran with minimal supervision. Multi-agent setups handled reconnaissance, exploitation and data theft against several victims at once, for hours or days at a time.
Anthropic note two caveats. Humans kept the decisions that matter to them, including target selection and monetisation.
Autonomy also raises speed and scale rather than severity. Several of the worst compromises came from operations a human directed at every step.
A criminal market in stolen AI credentials
Attackers now treat AI access as a prize. Anthropic describe stolen keys as delivering three things at once: resale value, compute that runs at the victim's expense and cover, since the activity appears under the legitimate owner's name.
One group ran fraudulent resellers advertising cheap access to Claude. Customers believed they were buying a discount. Their traffic went quietly to a different model while the reseller's software harvested their credentials and sold them onward.
In every case, the stolen keys came from customer environments. Anthropic state that their own systems were not compromised.
Influence operations ran as a commercial service
The report also details nine influence operations originating in Russia, Iran, Turkey and across the Gulf, South Asia, Africa and Europe, targeting audiences on six continents. Several timed their campaigns to national elections.
One France-based advertising agency ran roughly 70 fabricated news sites that published 8,913 articles in about 20 languages, shifting political position according to who was paying. An Istanbul company sold an election manipulation platform that managed around a thousand fake accounts targeting Malaysian voters.
Most of that content reached almost nobody. Anthropic tend to catch these operations before they launch.
What the AI security risks mean for an SME
Two findings reach a business under 250 people directly.
The first is the supply chain. In one case the operators breached a software provider and used that foothold to reach data belonging to around 200 of its downstream customers.
Those customers did nothing wrong. They bought ordinary business software from an ordinary supplier, which is why supplier data governance has become a live control rather than a procurement formality.
Where AI security risks enter through your own tools
The second is the fake reseller trade. A cost-conscious business hunting a cheaper route to frontier models is precisely the customer that scheme targets.
Attackers also mine public code repositories, app files, container images and websites for exposed credentials at industrial volume. A key left in a developer's repository two years ago gets found in an afternoon.
Anthropic put the lesson plainly, which is that security through obscurity has stopped working. Size no longer buys invisibility, because overlooking a small target now costs an attacker almost nothing.
Why your team need to understand this
None of it arrives through the front door. A firewall alone stops none of it.
An employee who signs up to a discounted AI service to save money has created the exposure. A developer who hardcodes an API key into an app has created it.
However, neither broke a rule, because nobody had written one. They moved quickly with tools their employer never governed.
What to put in place
Find out which AI tools your team use, including the ones nobody approved. Buy AI access only through the vendor or an authorised partner. Treat any offer that routes your traffic through an unfamiliar intermediary as a threat rather than a bargain.
Treat AI keys and agent integrations as production credentials. Rotate them, scope them and keep them out of code repositories.
Then write the rules down and teach them. An AI policy nobody has read changes nothing, which is why AI training and AI compliance work as a pair. Much of it overlaps with duties you already owe under the EU AI Act.
Plenty of consultancies will tell a client what to buy. We will tell them when to wait, in writing, before they spend a penny.
Frequently asked questions
Does the report mean businesses should stop using AI?
It concerns criminal misuse rather than any flaw in legitimate use. Anthropic disrupted each operation, strengthened their safeguards and shared intelligence with authorities. The practical response is deliberate adoption with controls.
Do attackers target smaller businesses?
Victims spanned education, retail, energy, healthcare, finance, manufacturing and government. Attackers reached several through their software suppliers rather than directly, which brings any company that buys business software into scope.
What are the main AI security risks for an SME right now?
Exposed API keys, unauthorised AI tools bought outside official channels and compromise arriving through a software supplier. All three are governance problems with practical fixes.
How do we know if an AI tool is safe for business use?
Check the provider's retention and training policy and confirm they offer a Data Processing Agreement under UK GDPR. Treat any route that requires sending credentials through a third party as unsuitable.
Understanding AI security risks costs a business very little, though acting on them after a breach costs a great deal. Our free AI Readiness Assessment takes two minutes and shows where your exposure sits.


