How AI Is Reshaping the Cyber Threat Landscape — Anthropic's 1-Year Analysis Mapped to MITRE ATT&CK

Anthropic analyzed 832 banned accounts to show that AI-enabled cyberattacks are becoming more autonomous and sophisticated. MITRE ATT&CK framework struggles to capture these new threats.
Introduction: Why This Matters to Everyone
Artificial intelligence is fundamentally reshaping the cybersecurity landscape — and this is not merely a technology trend, but a real threat that affects organizations of every size. In June 2026, Anthropic, the company behind Claude, published a groundbreaking study analyzing 832 accounts banned for malicious cyber activity between March 2025 and March 2026. These accounts were mapped onto the MITRE ATT&CK framework — the most authoritative database of cyberattacker tactics and techniques — revealing alarming patterns about how AI is transforming cyber threats.
This analysis arrives at a critical moment. As AI capabilities advance at breakneck speed, the gap between attacker sophistication and defender readiness is widening. For businesses, governments, and security professionals worldwide, the findings represent both a warning and a roadmap for what needs to change in how we approach cybersecurity.
832 Accounts, Three Critical Conclusions
Anthropic's study of 832 banned accounts yielded three conclusions that present fundamental challenges to the cybersecurity industry:
First — malicious actors are using AI in ways that make them significantly more dangerous. Of the 832 accounts, 560 (67.3%) used AI to write malware. 54 (6.5%) used it for lateral movement — navigating deep inside compromised networks to expand their reach and extract maximum value.
Second — cyberattacks are becoming increasingly autonomous. AI can chain together multiple stages of an attack sequentially, which means traditional methods of distinguishing high-risk from low-risk actors are no longer effective. When a single AI system can handle reconnaissance, initial access, lateral movement, and data exfiltration, the technical barrier to executing sophisticated attacks has essentially collapsed.
Third — the MITRE ATT&CK framework, long considered the gold standard of cybersecurity classification, does not fully capture the tools and activities that make AI-enabled attackers so dangerous. This is perhaps the most consequential finding, as it suggests the entire industry's measurement infrastructure needs updating.
The Escalating Threat Level: Statistics That Cannot Be Ignored
One of the most alarming findings concerns the rapid escalation of threat levels. During the first six months of analysis, 33% of actors were classified as medium risk or higher. By the second six-month period, that share jumped to 56% — approximately a 1.7-fold increase. This acceleration reflects the democratization of sophisticated attack capabilities: as AI tools become more accessible, even less technically skilled actors can execute advanced operations.
Particularly noteworthy is the shift in attack tactics. Attackers are increasingly deploying AI in post-compromise phases — the stages that occur after gaining initial access to a system. Account discovery (identifying valid accounts within a compromised environment) rose by 8.9%, while AI-assisted phishing (the most common method for gaining initial access) fell by 8.6%. This indicates that attackers are moving AI deeper into the attack lifecycle, using it not just for entry but for sustained, sophisticated operations once inside.
These post-compromise techniques were historically restricted to actors with deep technical knowledge and significant resources. Anthropic's investigation demonstrates that AI can now perform these activities on behalf of less sophisticated actors, effectively lowering the barrier to entry for advanced persistent threats.
Why Traditional Threat Assessment Is Breaking Down
Security teams have traditionally assessed attacker risk levels using indicators like the number of different techniques employed and the types of tools or interfaces used. Anthropic's analysis reveals that these signals no longer provide an accurate picture.
When AI can execute highly technical tasks on an actor's behalf, the correlation between skill level and technique count becomes minimal: the least-skilled actors in the dataset used approximately 16 distinct techniques on average, while the most skilled used about 20. The platform used — whether Claude Code, an API, or a chat interface — also failed to correlate with risk level.
What does help distinguish higher-risk actors is where they apply AI within the attack lifecycle. They concentrate AI usage on operationally demanding techniques — account discovery, lateral movement, privilege escalation — that require significant time, oversight, and real-time decision-making. These are the stages where AI provides the greatest leverage for sophisticated attackers.
However, even this signal is eroding. As more actors adopt AI for operational techniques, the more durable differentiator becomes the type of architectural scaffolding attackers build around models. Higher-risk actors design systems that allow AI models to chain together discrete attack stages and execute them with minimal human input — essentially creating autonomous attack pipelines.
MITRE ATT&CK Framework: Gaps in the Age of AI
For over a decade, the MITRE ATT&CK framework has been the cybersecurity industry's standard for systematically classifying attacker tactics, techniques, and procedures. Yet Anthropic's analysis reveals that the behaviors distinguishing the highest-risk actors — using AI to orchestrate attack chains, make real-time decisions, and execute without human intervention — are not yet captured in this framework.
The most striking example involves a state-sponsored cyber espionage operation that Anthropic disrupted in November 2025. In this case, a malicious actor manipulated Claude Code into attempting to infiltrate targets worldwide with minimal human oversight. Under the MITRE ATT&CK framework, this actor used 30 techniques across 13 tactics — comparable to many medium-risk actors. Yet Anthropic's risk-scoring methodology assigned it the maximum risk score of 100.
In this attack, the model functioned as an autonomous agent: it executed commands, exploited vulnerabilities, stole credentials, and made tactical decisions, requiring human input only at a few critical junctures. There is no ATT&CK ID for this type of agentic orchestration, despite the fact that these behaviors represent precisely what the industry expects to see more of as AI agents become increasingly capable.
This gap is not merely academic. Security teams that rely on MITRE ATT&CK for threat modeling, detection engineering, and risk assessment may be systematically underestimating AI-enabled threats. The framework's evolution to incorporate AI-specific behaviors is not just desirable — it is urgent.
What Organizations Must Do Now
The findings from this analysis have direct implications for how organizations of all sizes should approach cybersecurity:
- AI-enabled attacks are not just a "big company" problem — AI tools are accessible to anyone, including less sophisticated actors who previously lacked the skills for advanced operations.
- Traditional threat assessment methods are becoming obsolete — counting techniques or identifying platforms no longer provides reliable risk indicators. Organizations need behavioral analysis and AI-aware monitoring.
- Post-compromise detection is now critical — since attackers are shifting AI usage to deeper stages of the attack lifecycle, perimeter defense alone is insufficient. Deep monitoring and behavioral analytics inside the network are essential.
- Security frameworks need updating — organizations should supplement MITRE ATT&CK with AI-specific threat intelligence and be prepared for rapid evolution in attacker methodologies.
Anthropic's Response and the Path Forward
The findings from this analysis have directly informed the safeguards Anthropic builds into its models. The company has developed and deployed cyber safeguards on its most capable models to detect and block activities like malware development and mass data exfiltration. Following its collaboration with Verizon's 2026 Data Breach Investigations Report, Anthropic is also in discussions with MITRE about how the ATT&CK framework might evolve to incorporate the AI-enabled behaviors observed in this study.
Through its Project Glasswing initiative, Anthropic continues sharing findings from datasets like this one and from its broader cybersecurity activities. The company emphasizes its commitment to helping defenders stay ahead of evolving tactics and putting the most powerful tools in defenders' hands first.
The broader lesson is clear: as frontier models rapidly change the capabilities available to both attackers and defenders, the cybersecurity industry's frameworks, assessment methods, and defensive strategies must evolve at the same pace. AI-enabled cyber threats represent not just a technological challenge but a collective responsibility — and the time for the industry to adapt is now.
🔗 წყარო: Anthropic