Blog | Aztech IT Solutions

Anthropic’s September 2026 threat report means for UK businesses | Aztech

Written by Sean Houghton | 12 Sept 2026, 09:10:15

Anthropic just published a threat intelligence report covering eight months of the worst misuse of its Claude models: Russian espionage crews, student hackers, fake dating apps, a surveillance platform watching an entire country's phone network.
It's long and dense, and most of the headlines focused on bioweapons and drones.

I have read it twice now, and I'll be honest: the second read is what made me write this. Because the part that matters to a UK business with 100 staff and a Microsoft 365 or Google Workspace tenant is not in the headlines at all.

Here it is in one line.

AI did not invent a new kind of cyber attack. It made the old ones so cheap and fast that mid-sized firms are now worth hitting.

The attacks in this report are the ones you already know: stolen passwords, phishing, unpatched systems, leaked API keys. What changed is the economics. And the economics changed for the people attacking you, not for the people defending you.

This piece is the practical translation: what the report says, the cases that should actually worry you, what to tell your staff, and what to do in the next 90 days. No doom. Just clarity and a checklist.

What Anthropic actually published

Between December 2025 and August 2026, Anthropic's Threat Intelligence team disrupted misuse across seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons, and illicit model distillation.

The report is written for other AI labs, governments and security teams. It is not written for managing directors. That is why this piece exists.

Three of those seven areas matter to a UK small or mid-sized business day to day: cyber operations, scams and fraud, and the social engineering that now comes with both. The rest is serious national security material, but it should not distract you from the controls you can actually run this quarter.

The big idea: the tempo changed, not the attacks

For years, the most advanced campaigns needed specialist teams, custom tools and patience. That cost is what kept mid-market firms under the radar. Agentic AI has collapsed it. A lone operator can now run campaigns that a year ago would have needed a team.

Do not take my word for the speed. Take Anthropic's numbers:

  • One breach went from first access to bulk data theft in hours, not weeks
  • Another escalated from one stolen developer token to full admin control of the cloud estate in roughly three hours
  • Individual operators ran campaigns against dozens of victims in parallel

Two honest caveats from Anthropic itself, and they matter. First, humans are still choosing the targets and the monetisation. Second, autonomy is not severity: AI multiplies speed and scale, it does not make each individual attack cleverer. Several of the worst breaches in the report had a human directing every step.

So the right response is not panic. It is recognising that the report's own conclusion applies to you: security through obscurity is no longer viable. Everything connected to the internet is a potential target now, including the obscure little SaaS configuration nobody outside your business has ever looked at.

The case that will stay with me: the hotel Wi-Fi

One case in the report deserves its own section, because it is the most relatable thing in it.

A Russia-linked espionage group, tied by public reporting to Microsoft's Midnight Blizzard naming, compromised at least three hospitality vendors: the companies that run guest Wi-Fi for hotels. Not the hotels themselves, the vendors behind them.

With stolen admin credentials they hijacked the networks' DNS, so guests connecting to hotel Wi-Fi had their traffic and device details sent to attacker servers and were served "update" prompts. Install the fake update and you installed their malware, on Windows, Android and iOS.

Microsoft documented the technique as CaptiveCrunch in July 2026.

If your staff travel and open laptops in hotels, that is this report talking about your people. The protections are old and boring, which is the theme of this whole piece:

  • Patch laptops before they travel
  • Treat any update prompt that appears the moment you connect to Wi-Fi as hostile
  • Prefer tethering or a VPN on the road

Tell your team this week

Copy-paste this into an all-hands note or a Teams post. Keep it short. Every line traces back to a real case in the report.

  1. Do not install "cheap Claude" or "cheap ChatGPT" tools from adverts, random sites or download links. Buy AI through official channels or the company's approved list only.
  2. Urgent money, access or "the CEO needs this now" requests get a second check on a known phone number or in person. Never in the same thread that asked.
  3. Odd MFA prompts you did not trigger: deny and tell IT. Do not approve "just in case".
  4. A supplier or IT provider asking for tenant admin, API keys or a quick screen-share out of the blue: pause and verify through your normal contact route.
  5. Personal AI accounts, browser extensions and API keys have no place with company data. If it is not approved, it does not touch customer files.
  6. Hotel and airport Wi-Fi: no installs, no updates, no sign-ins that appear as pop-ups when you connect.

That is the staff half. The rest of this article is for leaders and IT.

Six ideas from the report, translated

1. Sophisticated attacks no longer need sophisticated attackers

The clearest proof in the report: two of the operators behind a sustained espionage campaign were undergraduate students.

Their exploit foundry used swarms of AI agents to research zero-day vulnerabilities around the clock, including against a major endpoint security product, validated in their own lab. One workflow produced more than a dozen possible zero-day findings in a single month.

They kept persistent campaign memory between sessions, and ran a thirteen-agent collection fleet that kept working while they slept. Roughly fifty organisations were targeted.

Five years ago that was a state program. Today it is two students and an API budget.

Figure from Anthropic's September 2026 threat intelligence report: the appliance zero-day research loop. Source

Watch for: "we're not interesting enough to be a target" as your main risk argument. It has aged badly. Also watch for one person holding Global Admin, finance approval and SaaS owner rights with no clear owner for new AI tools.

Warn staff: Attackers do not need to look like a Hollywood hacker. Treat unusual requests as unusual, even when the writing is perfect.

Protect: separate admin roles from day-to-day accounts. MFA on email, VPN, banking and Microsoft 365 admin. A named owner for AI tooling, not "whoever found a free trial".

2. AI is the orchestrator now, not the chatbot

This is not "someone asked ChatGPT how to hack".

In multiple cases, multi-agent setups did reconnaissance, exploitation and data exfiltration while a human set targets and reviewed the haul. Anthropic calls the style vibe hacking: the operator says "get useful data from this environment" and lets the model figure out the steps, often without the operator ever understanding the target environment themselves.

Figure from Anthropic's September 2026 threat intelligence report: attack lifecycle and AI integration. Source Figure from Anthropic's September 2026 threat intelligence report: sourcing and recon. Source Figure from Anthropic's September 2026 threat intelligence report: expand in-victim. Source

Watch for: agents or copilots that can change systems, send email or export bulk data with no human approval. Shared "team" API keys with no per-person logging. Shadow agents in personal accounts running company data.

Warn staff: An AI agent is not a toy. If it can read your mailbox or files, treat it like a junior colleague with keys to the office.

Protect: inventory every copilot, agent and AI extension. Scope them tightly and log what they do. Require a human to approve infrastructure changes, code deploys, money movement and bulk data exports.

3. Malware that rewrites itself when you catch it

In one espionage case, AI agents monitored whether the group's malware had been flagged by security products. When it was, other agents modified and rebuilt it until it slipped past again.

Anthropic's conclusion is blunt: if attackers can close that loop faster than vendors ship new signatures, static antivirus alone is a weaker brake than it used to be. Some payloads even froze the victim machine's security updates so that new signatures never arrived at all.

Watch for: "our antivirus says we're fine" as the whole strategy. Unpatched firewalls, VPN appliances and remote access gateways. No tested restore from backup in the past year.

Warn staff: If a laptop or account starts behaving oddly, say something early. Speed matters more when attackers can iterate overnight.

Protect: modern endpoint detection rather than legacy antivirus. A fixed patching rhythm for internet-facing systems, with emergency slots for critical CVEs. Identity controls, email security and offline or immutable backups, so one missed detection is not game over.

4. Your AI keys are loot, compute and cover

The most useful section of the report for day-to-day IT, in a grim way. When attackers steal your AI API keys they gain three things at once:

  1. Loot: keys sell in established criminal markets
  2. Compute: their attack workloads run on your bill
  3. Cover: the activity is attributed to you

How are keys harvested?

One crew mass-downloaded 1.8 million Android APK files and scanned them for hardcoded secrets, routing verified finds to a Telegram group in real time. Others run fake "cheap Claude" reseller sites and spoofed Claude Code installers that harvest every credential on a victim's machine, then keep harvesting as new sessions appear.

In the stolen-key cases in this report, the keys came from customer environments. Anthropic's own systems were not compromised.

Figure from Anthropic's September 2026 threat intelligence report: credential harvesting through to extortion. Source

Watch for: keys in Slack, Teams, Notion, repos or "temporary" staging sites that never died. Unexpected AI spend with no matching internal project. Staff installing unofficial AI desktop apps.

Warn staff: Never paste an API key into a chat "just for a minute." Never download an AI app because an advert promised it cheaper. If it is not on the approved list, stop and ask IT.

Protect: inventory keys and tokens the way you inventory admin passwords. Vault them, rotate anything that has ever been shared, restrict which apps can hold production keys, and alert on unusual AI spend where your provider allows it.

5. One SaaS foothold can become 200 customers' problem

One crew in the report specialised in supply-chain theft: breach a SaaS provider, then reach downstream. In a single case they pulled data belonging to roughly 200 of the provider's customer organisations, then dumped more than 2,100 Azure AD token sets across 40-plus tenants in about 34 hours. AI agents did nearly all of the work.

If you supply IT to others, read that again from the other side.

Figure from Anthropic's September 2026 threat intelligence report: common opportunistic workflows. Source

Watch for: vendors with broad Microsoft 365 or finance access and thin onboarding paperwork. Integration accounts that never expire. No list of which supplier can reach which system.

Warn staff: A message that looks like it came from a supplier is not automatically safe. Confirm unusual access requests through your normal supplier contact, not the email that asked.

Protect: ask every high-access vendor five questions:

  1. Where do you store admin tokens and AI API keys?
  2. How do you separate our tenant from your other customers?
  3. Who approves an agent or automation that touches customer data?
  4. How fast can you revoke a compromised integration?
  5. What logging do we get when something goes wrong?

These are the questions I would ask any supplier, and the ones I expect to answer when a client asks us.

6. Scams and fake personas got cheaper, not smarter

The report also covers fraud at industrial scale. One network of more than 20 dating apps mixed roughly 4,700 AI personas into the same swipe feed as real, recruited humans, about three bots for every one real person.

Over two weeks the personas exchanged around 2.4 million messages with at least 25,000 real people, with the AI instructed never to reveal what it was. The influence operations mostly failed to reach genuine audiences unless they rode real distribution channels such as state media.

The lesson for a UK business is simpler than geopolitics: fluent copy, a realistic photo and a professional manner now prove nothing.

Figure from Anthropic's September 2026 threat intelligence report: fraud account factory. Source Figure from Anthropic's September 2026 threat intelligence report: inauthentic accounts with AI-generated profile photos. Source

Watch for: payment-change requests and "new bank details" from a known name on a new channel. Rushed commercial approaches. Helpdesk-style calls asking staff to read back MFA codes.

Warn staff: If the request involves money, access or secrecy, verify out of band. A realistic photo and fluent English prove almost nothing now.

Protect: dual control on payment detail changes. Callback rules for finance and IT. Phishing refreshers that show AI-written examples, not just the old broken-English ones. A culture where people report near-misses without embarrassment.

Mini glossary

  • API key: a secret password that lets software call an AI or other service. Stolen, it spends your money and carries your name.
  • Agent / agentic AI: software that does multi-step tasks with less hand-holding than a chat. Powerful for your work, and for attackers.
  • Vibe hacking: Anthropic's phrase for operators who give AI a goal and let it improvise the technical steps.
  • Shadow AI: staff using unofficial AI tools or personal accounts with company data, outside IT's view.
  • SaaS supply chain: breaking into one cloud provider to reach many of its customers.
  • Kill chain: the sequence of steps in an attack, from finding a target to stealing data.
  • Distillation: copying an AI's capabilities by harvesting millions of its answers. Mostly a lab problem, but it is why "mystery discount AI" is a red flag.

What to do: 30 / 60 / 90 days

You do not need to become a threat intelligence analyst. You need a short, concrete plan.

Next 30 days

  1. Send the staff note above, or your version of it.
  2. Inventory AI access: copilots, agents, API keys, browser extensions, shadow IT included. Name an owner for each.
  3. Rotate any AI key that has lived in chat, email, a ticket or a shared doc.
  4. Confirm MFA on Microsoft 365, email, VPN and finance systems.
  5. List the suppliers that can reach your tenant, finance systems or customer data.

By 60 days

  1. Vault AI keys and purge them from code, demos and staging leftovers.
  2. Ban unofficial "cheap AI" shortcuts in policy and procurement. Official channels only.
  3. Put human approval on agent actions that change infrastructure, move money or export large datasets.
  4. Ask your top high-access vendors the five questions, and answer them yourself if you are the MSP.
  5. Test a backup restore for something that would genuinely hurt if ransomware landed tomorrow.

By 90 days

  1. Map all of this to Cyber Essentials or Cyber Essentials Plus if you are not already certified or renewing.
  2. Produce a one-page board brief from your IT lead or MSP: where the keys live, which agents exist, which suppliers matter most, done versus open.
  3. Tabletop a supplier compromise: "our CRM vendor's token was stolen, what do we do in the first four hours?"
  4. Review AI spend and logs monthly, so a stolen key shows up as noise, not a surprise invoice.

The NCSC's small business guidance pairs well with this list if you want an official anchor alongside Cyber Essentials.

Closing

Anthropic did the industry a favour by publishing this. Most business owners will never finish the report, and that is fine: that is what this piece was for.

The takeaway is not panic. It is clarity:

  • Mid-sized firms are more reachable than they were
  • AI keys and agents are now part of your attack surface
  • Staff need clear, boring rules for money, access and unofficial tools
  • The familiar controls still work, if you point them at the new tools
  • Secure AI adoption is governance and hygiene, not a slogan

That last line is the one I would take into your next leadership meeting, because it has never been the model. It is the setup around it.

If you want help turning this into a practical review of your Microsoft 365, SaaS and AI footprint, that is the kind of work Aztech does with UK organisations every week.

One question before you close the tab: of the five things on the 30-day list, which could you not honestly tick today? That one is your priority, and it is the one I would most enjoy writing the follow-up about.

Primary source: Anthropic threat intelligence report, September 2026