Anthropic just published a threat intelligence report covering eight months of the worst misuse of its Claude models: Russian espionage crews, student hackers, fake dating apps, a surveillance platform watching an entire country's phone network.
It's long and dense, and most of the headlines focused on bioweapons and drones.
I have read it twice now, and I'll be honest: the second read is what made me write this. Because the part that matters to a UK business with 100 staff and a Microsoft 365 or Google Workspace tenant is not in the headlines at all.
Here it is in one line. ⤵
AI did not invent a new kind of cyber attack. It made the old ones so cheap and fast that mid-sized firms are now worth hitting.
The attacks in this report are the ones you already know: stolen passwords, phishing, unpatched systems, leaked API keys. What changed is the economics. And the economics changed for the people attacking you, not for the people defending you.
This piece is the practical translation: what the report says, the cases that should actually worry you, what to tell your staff, and what to do in the next 90 days. No doom. Just clarity and a checklist.
Between December 2025 and August 2026, Anthropic's Threat Intelligence team disrupted misuse across seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons, and illicit model distillation.
The report is written for other AI labs, governments and security teams. It is not written for managing directors. That is why this piece exists.
Three of those seven areas matter to a UK small or mid-sized business day to day: cyber operations, scams and fraud, and the social engineering that now comes with both. The rest is serious national security material, but it should not distract you from the controls you can actually run this quarter.
For years, the most advanced campaigns needed specialist teams, custom tools and patience. That cost is what kept mid-market firms under the radar. Agentic AI has collapsed it. A lone operator can now run campaigns that a year ago would have needed a team.
Do not take my word for the speed. Take Anthropic's numbers:
Two honest caveats from Anthropic itself, and they matter. First, humans are still choosing the targets and the monetisation. Second, autonomy is not severity: AI multiplies speed and scale, it does not make each individual attack cleverer. Several of the worst breaches in the report had a human directing every step.
So the right response is not panic. It is recognising that the report's own conclusion applies to you: security through obscurity is no longer viable. Everything connected to the internet is a potential target now, including the obscure little SaaS configuration nobody outside your business has ever looked at.
One case in the report deserves its own section, because it is the most relatable thing in it.
A Russia-linked espionage group, tied by public reporting to Microsoft's Midnight Blizzard naming, compromised at least three hospitality vendors: the companies that run guest Wi-Fi for hotels. Not the hotels themselves, the vendors behind them.
With stolen admin credentials they hijacked the networks' DNS, so guests connecting to hotel Wi-Fi had their traffic and device details sent to attacker servers and were served "update" prompts. Install the fake update and you installed their malware, on Windows, Android and iOS.
Microsoft documented the technique as CaptiveCrunch in July 2026.
If your staff travel and open laptops in hotels, that is this report talking about your people. The protections are old and boring, which is the theme of this whole piece:
Copy-paste this into an all-hands note or a Teams post. Keep it short. Every line traces back to a real case in the report.
That is the staff half. The rest of this article is for leaders and IT.
The clearest proof in the report: two of the operators behind a sustained espionage campaign were undergraduate students.
Their exploit foundry used swarms of AI agents to research zero-day vulnerabilities around the clock, including against a major endpoint security product, validated in their own lab. One workflow produced more than a dozen possible zero-day findings in a single month.
They kept persistent campaign memory between sessions, and ran a thirteen-agent collection fleet that kept working while they slept. Roughly fifty organisations were targeted.
Five years ago that was a state program. Today it is two students and an API budget.
Watch for: "we're not interesting enough to be a target" as your main risk argument. It has aged badly. Also watch for one person holding Global Admin, finance approval and SaaS owner rights with no clear owner for new AI tools.
Warn staff: Attackers do not need to look like a Hollywood hacker. Treat unusual requests as unusual, even when the writing is perfect.
Protect: separate admin roles from day-to-day accounts. MFA on email, VPN, banking and Microsoft 365 admin. A named owner for AI tooling, not "whoever found a free trial".
This is not "someone asked ChatGPT how to hack".
In multiple cases, multi-agent setups did reconnaissance, exploitation and data exfiltration while a human set targets and reviewed the haul. Anthropic calls the style vibe hacking: the operator says "get useful data from this environment" and lets the model figure out the steps, often without the operator ever understanding the target environment themselves.
Watch for: agents or copilots that can change systems, send email or export bulk data with no human approval. Shared "team" API keys with no per-person logging. Shadow agents in personal accounts running company data.
Warn staff: An AI agent is not a toy. If it can read your mailbox or files, treat it like a junior colleague with keys to the office.
Protect: inventory every copilot, agent and AI extension. Scope them tightly and log what they do. Require a human to approve infrastructure changes, code deploys, money movement and bulk data exports.
In one espionage case, AI agents monitored whether the group's malware had been flagged by security products. When it was, other agents modified and rebuilt it until it slipped past again.
Anthropic's conclusion is blunt: if attackers can close that loop faster than vendors ship new signatures, static antivirus alone is a weaker brake than it used to be. Some payloads even froze the victim machine's security updates so that new signatures never arrived at all.
Watch for: "our antivirus says we're fine" as the whole strategy. Unpatched firewalls, VPN appliances and remote access gateways. No tested restore from backup in the past year.
Warn staff: If a laptop or account starts behaving oddly, say something early. Speed matters more when attackers can iterate overnight.
Protect: modern endpoint detection rather than legacy antivirus. A fixed patching rhythm for internet-facing systems, with emergency slots for critical CVEs. Identity controls, email security and offline or immutable backups, so one missed detection is not game over.
The most useful section of the report for day-to-day IT, in a grim way. When attackers steal your AI API keys they gain three things at once:
How are keys harvested?
One crew mass-downloaded 1.8 million Android APK files and scanned them for hardcoded secrets, routing verified finds to a Telegram group in real time. Others run fake "cheap Claude" reseller sites and spoofed Claude Code installers that harvest every credential on a victim's machine, then keep harvesting as new sessions appear.
In the stolen-key cases in this report, the keys came from customer environments. Anthropic's own systems were not compromised.
Watch for: keys in Slack, Teams, Notion, repos or "temporary" staging sites that never died. Unexpected AI spend with no matching internal project. Staff installing unofficial AI desktop apps.
Warn staff: Never paste an API key into a chat "just for a minute." Never download an AI app because an advert promised it cheaper. If it is not on the approved list, stop and ask IT.
Protect: inventory keys and tokens the way you inventory admin passwords. Vault them, rotate anything that has ever been shared, restrict which apps can hold production keys, and alert on unusual AI spend where your provider allows it.
One crew in the report specialised in supply-chain theft: breach a SaaS provider, then reach downstream. In a single case they pulled data belonging to roughly 200 of the provider's customer organisations, then dumped more than 2,100 Azure AD token sets across 40-plus tenants in about 34 hours. AI agents did nearly all of the work.
If you supply IT to others, read that again from the other side.
Watch for: vendors with broad Microsoft 365 or finance access and thin onboarding paperwork. Integration accounts that never expire. No list of which supplier can reach which system.
Warn staff: A message that looks like it came from a supplier is not automatically safe. Confirm unusual access requests through your normal supplier contact, not the email that asked.
Protect: ask every high-access vendor five questions:
These are the questions I would ask any supplier, and the ones I expect to answer when a client asks us.
The report also covers fraud at industrial scale. One network of more than 20 dating apps mixed roughly 4,700 AI personas into the same swipe feed as real, recruited humans, about three bots for every one real person.
Over two weeks the personas exchanged around 2.4 million messages with at least 25,000 real people, with the AI instructed never to reveal what it was. The influence operations mostly failed to reach genuine audiences unless they rode real distribution channels such as state media.
The lesson for a UK business is simpler than geopolitics: fluent copy, a realistic photo and a professional manner now prove nothing.
Watch for: payment-change requests and "new bank details" from a known name on a new channel. Rushed commercial approaches. Helpdesk-style calls asking staff to read back MFA codes.
Warn staff: If the request involves money, access or secrecy, verify out of band. A realistic photo and fluent English prove almost nothing now.
Protect: dual control on payment detail changes. Callback rules for finance and IT. Phishing refreshers that show AI-written examples, not just the old broken-English ones. A culture where people report near-misses without embarrassment.
You do not need to become a threat intelligence analyst. You need a short, concrete plan.
The NCSC's small business guidance pairs well with this list if you want an official anchor alongside Cyber Essentials.
Anthropic did the industry a favour by publishing this. Most business owners will never finish the report, and that is fine: that is what this piece was for.
The takeaway is not panic. It is clarity:
That last line is the one I would take into your next leadership meeting, because it has never been the model. It is the setup around it.
If you want help turning this into a practical review of your Microsoft 365, SaaS and AI footprint, that is the kind of work Aztech does with UK organisations every week.
One question before you close the tab: of the five things on the 30-day list, which could you not honestly tick today? That one is your priority, and it is the one I would most enjoy writing the follow-up about.
Primary source: Anthropic threat intelligence report, September 2026