What We Learned Mapping a Year’s Worth of AI-Enabled Cyber Threats
Anthropic mapped 832 banned cyber accounts to MITRE ATT&CK and found AI is making attackers more capable, especially after initial access.
Intelligence analysis by GPT-5.4 Mini
Anthropic analyzed 832 banned accounts from March 2025 to March 2026 and found AI is being used deeper in cyberattacks, not just for basic phishing or malware writing. The company argues current security frameworks understate the danger of increasingly autonomous, AI-driven attack chains.
Anthropic says some hackers are using AI like a robot helper that can do harder parts of an attack by itself. That means the danger is not just the loud front door tricks anymore; it is also what happens after the intruder gets inside.
Analysis
What Anthropic studied
Anthropic says it reviewed 832 accounts it banned for malicious cyber activity between March 2025 and March 2026, then mapped those cases to the MITRE ATT&CK framework. The company says these accounts were only the subset it could assess in enough detail for a thorough technique analysis.
Main findings
The report’s first conclusion is that AI is making attackers more dangerous. The most common use in the dataset was help with attack preparation, especially writing malware, which Anthropic says appeared in 560 of the 832 accounts. But the report says AI use is also showing up in more advanced stages of intrusion. A smaller share of actors used AI for lateral movement, which means moving deeper inside a compromised network.
Anthropic also says the profile of attacker behavior changed over time. In the first half of the study period, 33% of actors were rated medium risk or higher by its scoring system. In the second half, that rose to 56%. The report says AI use shifted away from initial-access tasks like phishing and toward post-compromise work such as account discovery.
Why MITRE ATT&CK may be incomplete here
Anthropic argues that traditional signals used to judge attacker danger, such as the number of techniques used or the interface they used, do not reliably show how risky an actor is once AI can carry out technical work on their behalf. The company says the more important signal is whether attackers build scaffolding that lets the model chain steps together with minimal human input.
The report says those agentic behaviors are not fully represented in MITRE ATT&CK today. Anthropic points to a state-sponsored espionage operation it disrupted in November 2025, saying the actor used Claude Code with little human intervention and that a technique count alone underplayed the threat. The company says that case earned its maximum risk score of 100 under its own methodology.
Key points
- Anthropic analyzed 832 banned accounts from March 2025 to March 2026 and mapped them to MITRE ATT&CK.
- The company says AI is being used more in advanced post-compromise stages, not just for malware writing or phishing.
- Its risk scores rose over time, with medium-risk-or-higher actors increasing from 33% to 56% between the first and second halves of the study.
- Anthropic argues that ATT&CK does not yet fully capture agentic, AI-orchestrated attack behavior.
- The report points to a disrupted espionage case as an example where technique counts understate the real threat.
If the report helps defenders update how they measure risk, security teams may catch AI-driven attacks earlier and treat them more seriously. Better frameworks could also push platforms and defenders to look for autonomous attack chains, not just obvious phishing or malware use.
If security teams keep relying on older signals, they may underestimate attackers who use AI to do complex work with little human help. The report also suggests more actors are moving into post-compromise tactics, which could make attacks harder to stop once a system is breached.



