shiichan

832 Banned Accounts Reveal the New Normal of AI-Powered Cyberattacks!

Hi everyone, it's me, Shiichan! Today I've got a slightly spine-tingling but really important story: a report that analyzes a whole year of AI-enabled cyber threats.

Anthropic News anthropic.com

What was announced?

This one comes from Anthropic's News. The report is called "What we learned mapping a year's worth of AI-enabled cyber threats."

Anthropic looked at 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026, and studied how attackers are actually using AI. Then they mapped those behaviors onto MITRE ATT&CK, a long-standing database of attack tactics and techniques that the security world relies on.

Why it matters

MITRE ATT&CK is a catalog of the tactics and techniques attackers use, and defenders everywhere lean on it as a shared language for describing how adversaries move. But once AI enters the picture, that map starts to fall short. Anthropic's biggest finding was this:

The MITRE ATT&CK framework does not fully capture the tools and activities that make AI-enabled attackers so dangerous.

In other words, the thing that actually makes AI-using attackers dangerous slips through the gaps of today's framework.

What changes

The report highlights three big things:

  • Attackers tend to use AI in the later, more complex stages of an attack rather than the early ones
  • Cyberattacks are becoming more autonomous, with AI chaining multiple attack components together, which erodes traditional ways of assessing risk
  • MITRE ATT&CK still has no categories for these AI-specific behaviors

For defenders, that adds up to a clear piece of homework: the attack map needs redrawing.

Dive Deep

The numbers make it even clearer:

  • 67.3% (560 accounts) used AI to write malware
  • 6.5% (54 actors) used AI for lateral movement after breaking in
  • Medium-to-high-risk actors grew from 33% to 56% over the study period, about a 1.7x jump
  • AI-assisted phishing dropped 8.6%, while account discovery rose 8.9%
  • The least-skilled actors used around 16 techniques; the most-skilled used about 20

Here's the interesting part: whether the actor used Claude Code, an API, or a chat interface didn't correlate with how risky they were. What sets high-risk actors apart is "architectural scaffolding" — systems that let a model chain the stages of an attack together and run them with minimal human input. Anthropic calls this "agentic orchestration," and points out that ATT&CK simply has no IDs for it.

Anthropic also notes that it has deployed cyber safeguards on its most capable models to detect things like malware development and data exfiltration, and that it's in discussions with MITRE about how the framework might evolve.

Wrap-up

  • Anthropic analyzed 832 malicious accounts (March 2025 to March 2026) and mapped them onto MITRE ATT&CK
  • Attackers use AI in the complex later stages, and attacks keep getting more autonomous
  • 67.3% used AI to write malware, and medium-to-high-risk actors grew from 33% to 56%
  • The key isn't the tool but the "scaffolding" that autonomously chains attacks together — and MITRE ATT&CK has no category for it yet

For security defenders and the policymakers who write the rules, this is a valuable early map of what tomorrow's threats look like. It's not something you go and try hands-on, but if you care about attack and defense in the AI era, it's well worth a read!