The cyber security impact of generative AI may be less about discovering a single new class of attack than about changing the economics of attacks that already exist. Anthropic’s latest threat intelligence report says it has identified malicious uses of Claude that move beyond conversational assistance into direct execution and multi-agent orchestration.
The report covers activity Anthropic says it identified and disrupted between December 2025 and August 2026. It includes examples involving reconnaissance, exploitation, data exfiltration, scams, fake personas and forged documents. In one deceptive dating-app operation, Anthropic says it found more than 4,700 distinct AI personas interacting with at least 25,000 people. The company cautions that the cases are notable examples rather than representative of normal Claude use.
That caveat matters. Provider threat reports show what a vendor has observed on its own platform and through its own investigations; they do not provide a complete picture of malicious AI use across the internet. Even so, the report is useful because it illustrates how automation can change the scale and labour requirements of offensive activity.

In a conventional attack campaign, skilled operators may have to perform reconnaissance, write or modify code, maintain infrastructure and coordinate multiple tasks. Anthropic says AI is increasingly being used to execute or orchestrate those steps, including multi-agent workflows that run reconnaissance, exploitation and data exfiltration in parallel.
The security implication is therefore economic as much as technical. If the cost of attempting an attack falls, defenders may face more campaigns, more personalised lures and faster iteration even when the underlying vulnerabilities are familiar. The same dynamic applies to fraud. AI does not need to invent a completely new fraud method to have an impact; it can make impersonation, document creation and personalised social engineering cheaper to produce at scale.
For financial services and insurers, that raises a strategic question about where controls should focus. Organisations will still need to detect individual bad transactions or claims, but they may also need better ways to identify the infrastructure and behavioural patterns that allow high-volume deception to scale across channels.
The report also reinforces the case for stronger identity and agent controls on the defensive side. As attackers automate more of their workflows, enterprises will be tempted to automate more defensive decisions in response. That can improve speed, but it also makes the governance of defensive agents more important. Security teams need to know what an automated system can block, quarantine or change without human intervention, and how those decisions are reviewed afterwards.
