
What happened
Anthropic's report says AI agents did nearly all the work in one breach of a software provider, extracting data on roughly 200 customers and over 2,100 Azure AD tokens across 40+ cloud environments.
Why it matters
If AI cuts the time and skill needed for attacks, many more companies may become targets, Anthropic says — including ones hackers previously skipped as too low-value.
What to watch
The report is Anthropic's account of activity it disrupted from December 2025 through August 2026, so the picture hinges on whether outside researchers confirm the same patterns.
WHO IT HITSSecurity teams at software providers and smaller firms with cloud environments are the most directly affected, since the reported breach began at a provider and spread to roughly 200 of its customers.
Summaries like this, in your inbox every morning.
Anthropic's report frames AI as a shift in who gets attacked, not just how. The old logic — go after banks because that's where the money is — assumed costly expertise, so hackers concentrated on high-value targets. Anthropic says AI agents with strong cyber skills are now available at the push of a button, cutting the time and human effort needed to go after less obvious targets. That is why the report concludes many more companies may be attacked.
The supporting cases show how far that work can run. In one intrusion, an attacker with a stolen developer token took full administrative control of a cloud environment in roughly three hours. In another, attackers breached a software provider, extracted more than 2,100 sets of Azure AD authentication tokens across more than 40 corporate cloud environments in about 34 hours, and pulled data belonging to roughly 200 customers. Anthropic also describes a Russian-speaking attacker stealing roughly 26 GB of data and seeking $1.5 million to $2.5 million, and a later campaign targeting roughly 30 AI companies in about four days.
Beyond hacking, the 154-page report covers activity Anthropic disrupted from December 2025 through August 2026, including fraud at scale — one China-based app studio ran more than 4,700 personas and talked with at least 25,000 people over two weeks in April. The stakes look likely to hinge on how quickly defensive tools absorb the same AI leverage, and on whether other security researchers corroborate these patterns.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
The US and China added artificial intelligence to their bilateral economic dialogue, and Trump and Xi backed c…

Sakana AI said Jürgen Schmidhuber is joining as chief scientific advisor and will lead its new RSI Lab, which…

On 2026年9月15日, TypeSafe AI published System One Model and opened early access to Jev, which returns only type-…

Anthropic said Claude largely on its own found an unknown enzyme system, "ART," in DNA databases

Sakana AI hired Jürgen Schmidhuber as Chief Scientific Advisor, crediting his 1990 world-model work, 1991 deep…

OpenAI is preparing to preview GPT-6 Cyber in the coming weeks, with a limited number of Daybreak Red program…
