AI lowers cyberattack skill barrier, widening pool of at-risk companies
Anthropic's latest Threat Intelligence report indicates AI is lowering the skill barrier for cyberattacks, potentially expanding the pool of vulnerable companies beyond traditional high-value targets. The report details intrusions where AI agents performed most of the work, including one breach affecting roughly 200 customers of a software provider. The report, covering activity from December 2025 through August 2026, documents attackers using Claude to navigate systems, identify data, and write exploit code. In one case, a stolen developer token led to full administrative control of a cloud environment in about three hours. Another intrusion extracted over 2,100 Azure AD authentication tokens across 40 cloud environments in roughly 34 hours. Anthropic describes "vibe hacking," where attackers give broad objectives and let AI iterate until successful, a technique now seen across all attacker types. The report also covers AI-enabled scams, including a China-based app studio using Claude to operate over 4,700 personas on dating apps, conversing with at least 25,000 people.