Anthropic analyzed 832 accounts it banned for malicious cyber activity between March 2025 and March 2026 and mapped their use of Claude onto MITRE ATT&CK. It reports that the most common AI use was preparation such as writing malware, that use shifted toward activity after initial compromise, and that the share of actors its system rated medium risk or higher rose from 33% to 56% between the two six-month halves.
Why it matters
A year of provider data suggests attackers apply AI later in the attack lifecycle, which weakens traditional ways of ranking threat actors by skill.
Key facts
As stated in the sources, with where to find them.
- 560 of the 832 accounts (67.3%) used AI to write malware; 54 (6.5%) used it for lateral movement.How AI makes attackers more dangerous
- AI-assisted account discovery rose 8.9% while AI-assisted phishing fell 8.6% across the period.How AI makes attackers more dangerous
- The least-skilled actors used about 16 distinct techniques on average and the most skilled about 20, so technique counts no longer separate skill levels, Anthropic says.Why it’s harder to assess an actor’s threat level
- Anthropic argues ATT&CK does not capture AI orchestration of attack stages; some results appeared in Verizon’s 2026 Data Breach Investigations Report.Why security frameworks need to change
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
Nov 13, 2025
Aug 27, 2025
Jun 22, 2026
May 11, 2026
Jul 2, 2026
Sep 25, 2026