What We Learned Mapping a Year’s Worth of AI-Enabled Cyber Threats
Anthropic says banned accounts show AI is helping cyberattackers move deeper into compromised systems, not just write phishing emails. It says MITRE ATT&CK misses key agentic behavior.
Intelligence analysis by GPT-5.4 Mini
After mapping 832 banned accounts from March 2025 to March 2026 onto MITRE ATT&CK, Anthropic argues AI is shifting cyberattacks toward more autonomous, post-compromise operations. The report says current security frameworks undercount how dangerous these actors are.
Anthropic says bad actors are using AI like a smart helper that can do more than write messages. It can help them get into a system and then move around inside it, like a burglar with a tool that also knows which rooms to check next.
Analysis
What Anthropic studied
Anthropic says it reviewed 832 accounts banned for malicious cyber activity between March 2025 and March 2026 and mapped those cases onto MITRE ATT&CK. The accounts were a subset of all bans in that period, selected because there was enough detail to assess the attackers' techniques. The company says it also shared some of the findings in Verizon's 2026 DBIR.
What it found
The main finding is that AI is being used in ways that make attackers more capable. The most common use was preparation work, especially writing malware, which Anthropic says appeared in 560 of the 832 accounts. More advanced use was less common but more concerning: 54 accounts used AI to help with lateral movement, meaning movement deeper inside a compromised network.
Anthropic says the attack mix shifted over time. In the first six months of the study, 33% of actors were rated medium risk or higher by its scoring system. In the second six months, that share rose to 56%. The report also says AI use moved away from initial-access tasks and toward post-compromise work. Account discovery rose while AI-assisted phishing fell, suggesting attackers are using AI deeper in the attack chain.
The report also argues that older ways of judging threat level are weakening. The number of techniques used and the interface chosen, such as Claude Code, an API, or chat, did not line up cleanly with risk. Instead, the company says the bigger clue is whether attackers build scaffolding that lets models chain steps together, make decisions, and run with little human input.
Anthropic's bottom line is that MITRE ATT&CK does not fully capture this kind of agentic orchestration yet, even though it can represent the individual techniques involved in a campaign.
Key points
- Anthropic mapped 832 banned accounts for malicious cyber activity to MITRE ATT&CK.
- AI was used most often for malware writing, and less often for deeper post-compromise tasks like lateral movement.
- The share of actors classified as medium risk or higher rose from 33% to 56% across the study period.
- The company says technique counts and platform choice no longer correlate well with attacker risk.
- Anthropic argues MITRE ATT&CK does not yet fully describe agentic orchestration in AI-enabled attacks.
If defenders update their playbooks and scoring methods, they could spot AI-assisted intrusions earlier and judge risk more accurately. The report gives them concrete signs to watch for, like attack-stage chaining and minimal human input.
If security teams keep relying on old signals like technique counts or the tool interface, they may underestimate attackers who use AI to chain together an entire intrusion. The report says those post-compromise tactics are already becoming more common.



