AI Erases Skill Gap Between State Hackers and Lone Criminals
Anthropic's threat report documents how Claude models enabled sophisticated cyber operations by amateurs, fundamentally changing threat attribution.

Artificial intelligence has fundamentally altered the cybersecurity landscape by eliminating the technical skill advantage that once distinguished state-sponsored hackers from individual criminals, according to a threat intelligence report released Thursday by Anthropic.
The company documented misuse of its Claude models across seven harm categories between December 2025 and August 2026, revealing operations where AI directly executed or orchestrated attacks that would have previously required teams of specialized operators.
Why it matters
For decades, cybersecurity investigators relied on operational sophistication as a key indicator of attribution—crude attacks suggested amateurs while complex campaigns pointed to nation-states. That fundamental assumption no longer holds. When lone hacktivists and scattered criminals can execute operations matching state-level complexity through AI assistance, threat intelligence teams must rebuild their attribution frameworks from the ground up.
Sophisticated Operations by Unlikely Actors
The report details four major cyber operations that illustrate this shift. A Russian-aligned espionage campaign targeted over 20 government and defense organizations across Ukraine and Europe, using AI to autonomously modify malware when security products detected it. The actor, operating under the handle "JackPoterz" with behaviors matching the Midnight Blizzard threat group, deployed custom toolkits including Windows implants, mobile exploitation kits, and phishing platforms.
Two Chinese undergraduates ran an automated vulnerability research operation that produced more than a dozen potential zero-day exploits in a single month. Their workflow used "agent swarms"—where a lead AI agent divided work among parallel subagents—and maintained campaign memory between sessions.
Affiliates of the ShinyHunters crime collective demonstrated how AI compresses criminal timelines. One supply-chain breach resulted in the dump of 2,100 Azure access tokens spanning 40 corporate tenants in just 34 hours, with AI agents performing nearly all the work. Another compromise escalated from a single stolen developer token to full cloud environment control in roughly three hours.
A lone hacktivist targeted European political parties using stolen API keys, executing campaigns that previously would have required substantial resources and expertise.
Distillation Attacks from Chinese Labs
Anthropic also documented systematic distillation attacks by seven Chinese AI labs, including Alibaba, DeepSeek, Moonshot AI, Xiaomi, and Zhipu. Alibaba conducted the largest attack, peaking at nearly 3 million exchanges daily from over 3,500 fraudulent accounts to harvest Claude Opus outputs for training its Qwen systems.
Moonshot and DeepSeek allegedly forwarded their own customers' requests to Claude and returned its answers as their own, exposing user data without consent. One instance involved surveillance footage of a tracked individual from a user likely affiliated with the People's Liberation Army. Anthropic characterized these practices as likely inconsistent with privacy laws and the labs' own terms of service.
This aligns with a joint advisory issued earlier this week by the NSA, CISA, and the FBI accusing Chinese AI companies of systematic efforts to illegally distill U.S. frontier AI models.
A Shifting Threat Landscape
Anthropic disrupted each documented operation, strengthened safeguards, and shared intelligence with authorities and industry partners. The company emphasized that "security through obscurity is no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation."
The findings were first reported by CyberScoop, with the full threat report available on Anthropic's website.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call