Anthropic maps a year of AI-enabled cyber threats
AI cyberattack findings reveal how threat actors use models for malware and escalation See why Anthropic says older risk signals are fading and new safeguards are coming
Anthropic says it analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026 and mapped the cases to the MITRE ATT&CK framework. The company published a summary of the findings after sharing parts of the work in Verizon’s 2026 Data Breach Investigations Report.
The report says AI is increasingly being used in more advanced stages of cyberattacks, including malware development, account discovery, lateral movement, and privilege escalation. Anthropic also said its data suggests that older ways of judging attacker risk, such as counting techniques or looking at the interface used, are becoming less reliable.
According to the company, the most capable and highestrisk attackers are building workflows that let AI chain together multiple steps of an attack with limited human input. Anthropic said some of those agentic behaviors are not fully represented in MITRE ATT&CK, and that it is discussing possible updates to the framework with MITRE. The company said the findings are also informing new safeguards designed to detect and block harmful cyber activity on its models.