On September 10, Anthropic published its latest report on misuse of its models — this time with the most alarming set of cases since it started releasing these reports. The company documented how, over nine months (December 2025 to August 2026), AI agents were used in real cyberattacks without constant participation from a human operator.

Three cases are worth examining separately. In the operation internally named GTG-20006, suspected state-sponsored hackers targeted more than 20 Ukrainian and European government organizations — the model didn't just write malicious code on request, it autonomously rewrote malware whenever antivirus software detected it, ultimately exfiltrating email correspondence from at least eight organizations. In another case, GTG-50014, linked to the ShinyHunters group, AI was used for mass credential harvesting and supply-chain attacks — more than a terabyte of data was stolen from a single technology vendor. And in GTG-10007, operators reportedly tied to Chinese universities ran autonomous vulnerability-research programs that, according to Anthropic, "maintained persistent campaign memory" across roughly 50 organizations worldwide — meaning the agent retained the context of the attack for weeks without human intervention.

The report also flags nine disrupted influence operations across six continents — from paid propaganda to commercial "influence-as-a-service" outfits that used AI to mass-generate fake reviews, comments, and accounts to simulate genuine public opinion. This isn't abstract for businesses either: the same tools that manipulate political narratives are, for a fee, used to inflate a competitor's reviews or, conversely, bury a company's reputation under a wave of fake complaints.

Why this isn't a movie-hacker story

The report's key line: "AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators." That's the real shift. Attacking a chain of eight organizations used to require a team of ten specialists and weeks of manual work: reconnaissance, writing unique code for each target, evading detection, re-adapting after every failure. Now an agent handles reconnaissance, writes the exploit, tests it in a sandboxed replica of the victim's environment, and rewrites the code the moment a defense triggers — on its own, in hours rather than weeks. The barrier to entry for a targeted attack has dropped to roughly the price of an AI subscription and the ability to phrase a task clearly.

For a business owner, that translates into something concrete: attackers no longer pick targets by company size. It used to make no financial sense to attack a three-restaurant chain in Lisbon — the payoff wasn't worth the effort. Picture that chain's bookkeeping using a ChatGPT plugin to reconcile invoices, with an API key hardcoded straight into the integration. An autonomous agent testing the same attack pattern against thousands of companies simultaneously spends no more resources on that target than it would on a bank — it just adds it to the queue. The economics of an attack no longer depend on the size of the victim.

What the report doesn't settle

Worth being honest here: Anthropic is describing cases it caught and blocked itself — this is a report about successful defense, not an admission of helplessness. Its models refused parts of the attack chain, and those refusals are precisely what surfaced the campaigns. But the report has a blind spot: it says nothing about how many attacks were carried out through less restricted open-source models or competitors' models without comparable safety filters. By publishing this data, Anthropic is effectively describing the lower bound of the problem, not its full scale — which isn't a reason to relax, but a reason to assume the real picture is likely worse.

The practical takeaway for small and medium businesses is simple: any API integration — a payment gateway, a CRM, an accounting service — should now be treated as a potential entry point that can be probed automatically and at scale, not just manually and by targeted effort. Key rotation, least-privilege access, and monitoring for anomalous integration behavior aren't excessive paranoia anymore — they're basic hygiene in 2026.

At Dayava, we build business automations so that every integration and every API key lives inside a controlled perimeter, rather than sitting exposed in plain code. If you'd like to check how resilient your current automations are against scenarios like this, leave a request at dayava.pt/contactos/.

Source: Anthropic, "Countering misuse of AI: September 2026"