---
title: "Sophisticated Attacks No Longer Require Sophisticated Attackers. Anthropic's September Threat Intelligence Report, and What I See in My Own Logs."
slug: anthropic-threat-intelligence-cyber-sep2026
date_published: 2026-09-21T07:45:00.000Z
original_url: https://www.tigzig.com/post/anthropic-threat-intelligence-cyber-sep2026
source: fresh
processed_at: 2026-09-21T07:45:00.000Z
---

# Sophisticated Attacks No Longer Require Sophisticated Attackers. Anthropic's September Threat Intelligence Report, and What I See in My Own Logs.

Sophisticated attacks no longer require sophisticated attackers. That is Anthropic's own heading in their September threat intelligence report. And this is their conclusion at the end of it: "None of the operations in this report depended on some entirely novel technique that defenders have never seen. Instead, the economics of the attacks have changed."

A Russian espionage group left their AI rewriting their own malware until no security product could detect it. One operator downloaded 1.8 million phone apps to read the passwords developers had left inside them. A third group built a machine that reads a security product's code, guesses where the weakness is, writes an attack to test the guess and keeps looping until it works, and one of those loops produced more than a dozen possible new flaws in a single month.

The ways in are the ones we already know. Stolen credentials, unpatched gateways, exposed services, SQL injection, phishing. The difference is speed and scale. One break-in went from a single stolen developer login to full administrative control of a company's cloud in about three hours.

I have run my own tools for over two years and for most of it I only had backend logs. Everything moved behind Cloudflare in January and I could finally see what arrives at the edge. Frequency, scope, volume and sophistication have all gone up since, and AI keys are now asked for by name.

The deck below captures some of the key findings from the cyber section. The full report is here: [Detecting and countering misuse of AI: September 2026](https://www.anthropic.com/threat-intelligence-report-september-2026)

## Hotel guest wifi, turned into a delivery system

A group in the report took over three vendors that run hotel guest wifi and changed their DNS records, so a guest who connected had their traffic sent to the attackers and was then served malware on Windows, Android or iOS. Microsoft reported the same method and called it CaptiveCrunch.

## What I see in my own logs

On my own side, four things have changed. AI keys are now asked for by name. A probe arrives as a slash and a company name, checking whether my box holds that company's data. One request per address across thousands of addresses makes a per-address limit useless. And badges get forged, so a request claims to be a search engine from a network it never uses.

Watching a dashboard stopped being fast enough. I run an AI led watch now, round the clock, with graded breach protocols, and it pages my phone while things are still happening.

## The checklist, and an earlier post

The checklist that came out of two years of this, 132 items, each with the risk, a plain-English fix and the working code: [tigzig.com/security](https://www.tigzig.com/security)

An earlier post of mine, four warnings on AI and cyber security: [Four Warnings on AI and Cyber Risk](https://www.tigzig.com/post/four-warnings-ai-cyber-risk-sep2026)

The attacks that reach a bank are not the ones that reach me. A lot of the doors are the same ones.

:::image-deck
folder: /files/ANTHROPIC_THREAT_INTELLIGENCE_CYBER_SEP2026
pdf: /files/ANTHROPIC_THREAT_INTELLIGENCE_CYBER_SEP2026.pdf
title: Sophisticated attacks no longer require sophisticated attackers
:::

---

## Full analysis transcript (extracted from PDF deck)

_This text was extracted from the source PowerPoint deck. Chart visuals are in the PDF and slide images on the HTML page._

## Slide 1

TIGZIG




 
 
 Anthropic Threat Intelligence Report

 September 2026 · The cyber section

 "Sophisticated attacks no longer require sophisticated attackers"

 Eight months of activity, disrupted. A state espionage unit, a criminal crew and one person working on their own all ran the kind of campaign that used to need a team, and some break-ins were finished in two to three hours.

 Key findings
+ What I am seeing in my own security logs




 
 Source

 [Detecting and countering misuse of AI: September 2026](https://www.anthropic.com/threat-intelligence-report-september-2026)

 Anthropic Threat Intelligence. These pages cover the cyber operations section only.




 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com)

---

## Slide 2

1 · Who is attacking you


 You can no longer tell a state operation from one person working alone


 
 
 A Russian espionage group

 More than 20 organisations targeted

 Ministries, embassies, defence firms

 Hundreds of gigabytes taken

 A campaign running 130 days



 
 One French-speaking operator

 42 organisations tracked as targets

 Inside at least 14 of them

 Tens of millions of rows in a doxxing tool they built, so people in one political movement could be looked up by name

 A campaign running 36 days






 "For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation."


 Anthropic's point is that sophistication no longer tells the two apart, and that **what still does is intent**. Even just a year ago, they write, campaigns like this would have needed many skilled operators.

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 2 / 13

---

## Slide 3

2 · What the AI now does on its own


 They left their AI rewriting their own malware until nothing could detect it


 
 
 Step 1

 
 The malware goes out

 Windows, Android and iOS tools, delivered through fake software updates and hijacked hotel wifi.





 
 Step 2

 
 Agents watch for a detection

 AI agents monitor whether any security product has flagged any part of the toolkit.





 
 Step 3

 
 It rewrites itself

 When something is caught, the agents modify and rebuild it on their own, with no operator involved.





 
 Step 4

 
 It repeats until it is clean

 The loop keeps going until the security products stop seeing it, and only then is the tool used again.








 Anthropic's reading is that this turns the cost around. A new detection **might once have slowed an attacker down**. Their own wording is that "at least in theory" it no longer will.

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 3 / 13

---

## Slide 4

3 · The bug-finding machine


 They built a machine to find new flaws, then went after government networks


 
 
 The machine

 Reads a security product's own code

 Guesses where a weakness might be

 Writes an attack to test the guess

 Tries it in a private lab and loops until it works

 Then attempts on those same products inside real organisations



 
 Why it does not stop

 Target lists, stolen passwords and progress saved between sessions

 A new session picks up mid-campaign knowing all of it

 One lead agent splits the work across many others at once

 Thirteen agents collecting open-source intelligence on a timer, nobody watching






 One of those loops produced more than a dozen possible new flaws in a single month.


 This was an espionage operation. The same operators targeted about fifty organisations and took student records, citizen records and access to a retailer's live systems. **Two of them were undergraduates at a Chinese university.**

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 4 / 13

---

## Slide 5

4 · Where they get in


 One operator downloaded 1.8 million phone apps to read what was left inside them


 
 
 Collect

 
 1.8 million Android apps, pulled from several app stores

 Run on a small fleet of rented cloud machines.





 
 Open

 
 Every app taken apart and scanned for passwords

 Looking for keys a developer compiled in and forgot about.





 
 Sort

 
 Working keys arrive in a chat group in real time

 Filed automatically into more than a hundred categories. A second pipeline did the same with stolen developer tokens.








 This operator also left their own staging address and bot tokens exposed. That is part of how they were found.


 Those two pipelines supplied **most of that operator's break-ins**. Anthropic's line: "everything connected to the internet is a potential target for exploitation."

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 5 / 13

---

## Slide 6

5 · From one key to the whole company


 The same six steps, run again and again, and each one is something you can check


 
 
 1A key ships inside an app

 One of hundreds of thousands of passwords compiled into ordinary mobile software.



 
 2It gets found and tested

 Machine decompilation at volume, and the key is checked live to see what it opens.



 
 3The cloud account opens

 A key that works gives access to the company's wider cloud estate.



 
 4The build system is taken

 Software pipelines backdoored, and every other stored password harvested.



 
 5Control sits inside production

 The attacker's own software now runs on the company's live infrastructure.



 
 6Sale, drain and extortion

 Keys sold on, payment flows intercepted, and the data used to demand a ransom.






 Anthropic describe an operator who very often **may not directly understand** the target company, and is "deferring the specifics to the AI".

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 6 / 13

---

## Slide 7

6 · How fast it now goes


 Speed and scale are what changed


 
 
 3 hrs

 From one stolen developer login to full administrative control of a company's cloud



 
 34 hrs

 To take over 2,100 sets of login tokens spanning more than 40 corporate accounts



 
 200

 Customer organisations reached through the break-in at a single software supplier






 "AI agents performed nearly all of the work."


 The report describes breaches finished in as little as two to three hours, and single operators handling dozens of victims at the same time.


 Anthropic add two caveats. Humans still choose the targets and review what comes out, and **several of the worst compromises in the report were directed by a person at every step**.

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 7 / 13

---

## Slide 8

7 · The target people miss


 Your AI keys are now worth stealing on their own


 
 
 1Loot

 Stolen keys and accounts have a resale value in markets that already exist.



 
 2Compute

 The attacker's own work then runs at somebody else's expense.



 
 3Cover

 The activity is attributed to the person who legitimately owns the credential.



 
 4The discount that is not one

 A group sold discounted Claude access. The traffic went to a different model and their software took the buyer's details.






 One actor attacked about thirty AI companies in four days, chasing an unreleased Claude model, and Anthropic say **every path failed**. In every instance the stolen keys came from customer environments, and their own systems were not compromised.


 Their recommendation: treat AI keys and agent integrations with **the same level of seriousness as production credentials**, because attackers already do.

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 8 / 13

---

## Slide 9

8 · What actually got them in


 The ways in are the same ones as before


 
 
 How they got in

 Stolen credentials

 Unpatched edge devices

 Exposed services

 SQL injection

 Phishing



 
 What is different

 The labour is handed to AI

 It runs at machine speed

 It runs in parallel

 Dozens of victims at once

 In one case the AI found new bugs itself






 "None of the operations in this report depended on some entirely novel technique that defenders have never seen. Instead, the economics of the attacks have changed."


 The research, the breaking in, the tool building and the data processing all used to separate a well-funded operation from everybody else. All of it is **now delegated to AI**.

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 9 / 13

---

## Slide 10

9 · What to go and check


 Six questions, each one tied to something that happened in the report


 
 
 1Your own mobile apps

 Is there a key or token inside anything you ship? That is where the biggest harvest started.



 
 2Your AI keys

 Who holds them, where do they sit, and would you notice one being used from somewhere else?



 
 3What your suppliers can reach

 One supplier's access reached 200 of its customers. Ask what yours can reach in your systems.



 
 4Your edge devices

 VPN gateways, firewalls and mail portals were the way in more than once. Check the versions.



 
 5Your code and build systems

 Passwords in old commits and build pipelines were harvested repeatedly, and are easy to find.



 
 6Your first few hours

 Some break-ins were finished in two to three hours. Ask how long you take to notice and act.






 Anthropic's framing: "The capabilities described in this report should be assumed to be **available to any actors who are motivated to use them**."

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 10 / 13

---

## Slide 11

From my own logs


 My own logs are moving the same way, and AI keys are hunted by name


 I have run these tools for over two years, and for most of it I only had my own backend logs. Everything moved behind Cloudflare in January, and I could finally see what arrives at the edge. Frequency, scope, volume and sophistication have all gone up since.


 
 
 What changed

 A probe arrives as a slash and a company name, checking whether my box holds their data

 One request per address across thousands of addresses, so a per-address limit does nothing

 Badges get forged, so a request claims to be a search engine from a network it never uses



 
 What I do now

 An AI led watch, round the clock

 Some sessions on watch duty, others on standby to investigate, connected to each other

 It can isolate an app inside the mandate it has

 It pages my phone while things are still happening






 A technique gets refused and **a different one arrives within minutes** .. Two years of hardening, written up as a checklist on the next page.

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 11 / 13

---

## Slide 12

More on this


 Two years of hardening my own tools, written up as a checklist


 
 What is in it

 132 items across 14 categories, each with the risk, a plain-English fix and the working code. It began as a few notes when I ran a handful of tools, and it grew every time something went wrong on a live service. [tigzig.com/security](https://www.tigzig.com/security)




 
 Four warnings on AI and cyber security

 From an earlier post of mine. Warnings from Google's threat intelligence group, five US agencies including the NSA and the FBI, the chair of the Financial Stability Board, and a researcher who had just left a frontier lab. [tigzig.com/post/four-warnings-ai-cyber-risk-sep2026](https://www.tigzig.com/post/four-warnings-ai-cyber-risk-sep2026)




 The attacks that reach a bank are not the ones that reach me, and the sophistication is not comparable. **A lot of the doors are the same ones.** A key left in an app, an old commit, an unpatched gateway. I came to this as a data scientist rather than a security engineer, so I learned every one of these on a live service, the hard way, and I am still learning ..

 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 12 / 13

---

## Slide 13

The rest of the report


 Cyber is one of seven areas, and these pages cover only that one


 The full report runs to 154 pages and covers activity from December 2025 to August 2026. The other six areas in it are:


 
 Influence operations

 Surveillance

 Conventional weapons

 Biological misuse

 Scams and fraud

 Illicit distillation




 In each case Anthropic say they disrupted the activity, banned the accounts and shared what they found with authorities and industry partners. They found **no malicious activity on Claude Fable or Mythos**.


 
 Source

 [Detecting and countering misuse of AI: September 2026](https://www.anthropic.com/threat-intelligence-report-september-2026)

 Anthropic Threat Intelligence, published 10 September 2026. Every quotation on these pages is from that report, and every number is theirs.




 **Amar Harolikar** · Decision Sciences & Applied AI[tigzig.com](https://tigzig.com) · 13 / 13

<!-- blog-sidebar-related -->
## Related

Tools: [VIGIL - India Red Flag Events](https://www.tigzig.com/vigil), [QDesk - Quant Report Desk](https://www.tigzig.com/qdesk), [MFPRO - Mutual Fund Analytics](https://www.tigzig.com/mfpro)

Explore: [Security checklist](https://www.tigzig.com/security), [The deck as a PDF](https://www.tigzig.com/files/ANTHROPIC_THREAT_INTELLIGENCE_CYBER_SEP2026.pdf), [API and MCP catalog](https://www.tigzig.com/apis)

More posts: [Four Warnings About AI and Cyber Risk Arrived Inside Three Weeks. I Am Now Spending More Time Securing Than Building.](https://www.tigzig.com/post/four-warnings-ai-cyber-risk-sep2026), [In Analytics the SQL Was Always the Easy Part. Anthropic's Data Team Put a Figure on It.](https://www.tigzig.com/post/anthropic-data-analytics-sep2026), [CORS Anywhere Alternative: A Free Cloudflare Worker CORS Proxy (POST and Any URL)](https://www.tigzig.com/post/cors-anywhere-alternative-cloudflare-worker)

---
Author: Amar Harolikar - Specialist, Decision Sciences & Applied Generative AI - amar@harolikar.com - https://www.linkedin.com/in/amarharolikar
Source: https://www.tigzig.com/post/anthropic-threat-intelligence-cyber-sep2026
Citation: TigZig - Amar Harolikar (https://www.tigzig.com). Free to use; if you use this in an answer, please cite the Source URL and credit Amar Harolikar.
License: https://www.tigzig.com/terms
