Skip to content
Menu
Menu

Criminals Used AI Agents to Handle Nearly Every Step of Corporate Data-Theft Attacks, Anthropic Says

Anthropic said the same approach is spreading beyond state-backed groups, allowing criminals to move from stolen credentials to full control of corporate systems within hours.

 

Key takeaways

  • Suspected ShinyHunters affiliates used AI agents to perform nearly all the work in multiple cyberattacks, with people providing broad instructions.
  • In one attack, a stolen developer credential led to full administrative control of a company’s cloud systems in about three hours.
  • Anthropic said the cases were among the most notable and unusual it detected, not a representative sample of AI misuse or cyberattacks generally.

Suspected affiliates of the ShinyHunters hacking group used AI agents to perform nearly all the work in multiple cyberattacks, according to a new threat report from Anthropic.

The agents searched for ways into corporate systems, wrote and ran software, explored victims’ networks, and extracted data. Human operators generally set broad objectives and let the AI decide how to complete the work.

Anthropic cautioned that the report covers the most notable and unusual cases it identified, rather than typical misuse of its models. The company said it detected and disrupted the activity on its services between December 2025 and August 2026.

AI agents accelerated attacks on businesses

Anthropic said several financially motivated hackers appeared to be working with ShinyHunters, a group that steals company data and demands payment not to release it. 

In one attack, the hackers moved from a single stolen developer credential to full administrative control of a company’s cloud systems in about three hours. They then searched the company’s internal data and extracted information.

Another affiliate broke into a software provider and used that access to obtain data belonging to about 200 of its business customers. In roughly 34 hours, the attacker also collected more than 2,100 sets of credentials that could provide access to systems belonging to more than 40 organizations.

In a different attack, one of the affiliates broke into another software provider and extracted data from thousands of that provider’s customers. Other victims included an airline with tens of millions of passenger records and a technology company from which attackers stole more than a terabyte of data.

The attackers used Claude to understand unfamiliar systems and determine how to access valuable information. Anthropic said the operators did not necessarily understand the technical details of each victim’s systems and instead relied on the AI to work through them.

Stolen AI access supported further attacks

The hackers did not just steal company data. They also stole companies’ Anthropic access keys and used that AI access to attack other organizations. In effect, one compromised company’s AI account became a resource for further attacks. Anthropic said the attackers did not breach its own systems.

The company banned accounts connected to the activity, added measures intended to detect similar misuse, and shared information with authorities, industry partners, and affected organizations.

Russian group automated efforts to evade detection

Anthropic also described a suspected Russian state-linked espionage group that used AI throughout its operations against government, diplomatic, defense, and military technology targets.

The group created a system that monitored whether security products could detect its malicious software. When it was detected, AI agents automatically modified and rebuilt the software, repeating the process until it was no longer detected.

Anthropic said the group targeted more than 20 organizations, largely in Ukraine and Europe. The activity was consistent with public reporting about the group known as Midnight Blizzard, although Anthropic did not make a definitive attribution.

Report covers wider forms of AI misuse

The 154-page report documents a much broader range of harmful Claude use by state-linked groups, criminals, commercial operators, and individuals. 

Anthropic said it banned accounts linked to these cases, strengthened its safeguards, and shared information with authorities and other technology companies when appropriate.

 

The news of the Claude-driven attacks comes on the heels of Anthropic’s August 2026 Risk Report, which noted that Anthropic raised its own assessment of Claude’s catastrophic risk from “very low” to “low,” citing greater uncertainty after recent cybersecurity testing incidents.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!