{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/anthropic-mapping-ai-cyber-threats-attack-2026/",
 "asOf": "2026-09-26",
 "id": "anthropic-mapping-ai-cyber-threats-attack-2026",
 "date": "2026-06-03",
 "datePrecision": "day",
 "title": "Anthropic maps 832 banned accounts onto MITRE ATT&CK and finds AI use moving deeper into attacks",
 "lane": "attack",
 "kind": "misuse-report",
 "summary": "Anthropic analyzed 832 accounts it banned for malicious cyber activity between March 2025 and March 2026 and mapped their use of Claude onto MITRE ATT&CK. It reports that the most common AI use was preparation such as writing malware, that use shifted toward activity after initial compromise, and that the share of actors its system rated medium risk or higher rose from 33% to 56% between the two six-month halves.",
 "whyItMatters": "A year of provider data suggests attackers apply AI later in the attack lifecycle, which weakens traditional ways of ranking threat actors by skill.",
 "actors": [
  "anthropic"
 ],
 "topics": [
  "threat-intelligence",
  "ai-enabled-intrusion",
  "standards-and-guidance"
 ],
 "atlas": [],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack",
   "publisher": "Anthropic",
   "title": "What we learned mapping a year’s worth of AI-enabled cyber threats",
   "date": "2026-06-03",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "560 of the 832 accounts (67.3%) used AI to write malware; 54 (6.5%) used it for lateral movement.",
   "locator": "How AI makes attackers more dangerous"
  },
  {
   "fact": "AI-assisted account discovery rose 8.9% while AI-assisted phishing fell 8.6% across the period.",
   "locator": "How AI makes attackers more dangerous"
  },
  {
   "fact": "The least-skilled actors used about 16 distinct techniques on average and the most skilled about 20, so technique counts no longer separate skill levels, Anthropic says.",
   "locator": "Why it’s harder to assess an actor’s threat level"
  },
  {
   "fact": "Anthropic argues ATT&CK does not capture AI orchestration of attack stages; some results appeared in Verizon’s 2026 Data Breach Investigations Report.",
   "locator": "Why security frameworks need to change"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "agent-orchestrated-intrusion"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}