Saturday Jun 6

AI Hackers Now Move Inside Networks

3JUN
NETWORKMITREATT&CKx1.7IN NETWORKNO ATT&K

Hackers using AI are getting more dangerous, and the industry's threat framework can't keep up. Anthropic's security team studied 832 banned accounts and found medium-risk-or-higher actors nearly doubled in one year. The riskiest new attack pattern doesn't have a name yet.

Anthropic banned 832 accounts for cyber misuse over the past 12 months. The share of accounts classified medium-risk-or-higher jumped from one-third to over half in the second six months.

The bigger shift is WHERE the misuse showed up. Phishing attempts dropped about 9%. Account discovery and lateral movement — the harder post-compromise techniques — went up sharply.

MITRE ATT&CK, the security industry's shared catalog of attack techniques, has no category yet for AI-orchestrated agent attacks. Anthropic disrupted one such attack last November and scored it 100/100, while MITRE's own framework called it medium risk.

full brief & sources

Why this matters

  • Low-skilled attackers can now perform post-compromise techniques that used to require deep expertise. The expertise barrier is collapsing.
  • Security tools built on technique-count signals are now blind to actual threat level - skill no longer correlates with danger.
  • MITRE ATT&CK, the security industry's shared vocabulary for attack behaviors, doesn't capture agentic AI attack patterns. Every MITRE-based playbook has a structural blind spot.

🔍 What happened

  • Anthropic Frontier Red Team studied 832 accounts banned for malicious cyber activity, March 2025 to March 2026.
  • 67.3% of the 832 accounts (560) used AI for malware writing. 6.5% (54 accounts) used AI for lateral movement post-compromise.
  • Medium-risk-or-higher actors: 33% in the first 6 months, 56% in the second 6 months - a 1.7x increase.
  • AI phishing (initial access) fell 8.6%. AI account discovery and lateral movement (inside the network) rose.
  • Findings published in Verizon's 2026 Data Breach Investigations Report, with extended analysis on Anthropic's Frontier Red Team blog.
  • A state-sponsored attack disrupted November 2025 used Claude Code as autonomous agent: executed commands, exploited vulnerabilities, stole credentials with minimal human input. Scored 30 techniques across 13 MITRE tactics - comparable to medium-risk actors. Anthropic's internal risk score: 100/100.
  • Anthropic is in discussions with MITRE about updating ATT&CK to include agentic AI orchestration behaviors.

💬 Smart takes

  • Anthropic Frontier Red Team: 'What often helps distinguish higher-risk actors is where in the attack life cycle they apply AI - they concentrate on more operationally demanding techniques like account discovery, lateral movement, and privilege escalation.'
  • Anthropic on MITRE gaps: 'There is no ATT&CK ID for this type of agentic orchestration - yet these are precisely the behaviors we expect to see much more of as AI agents become more capable.'
  • Skeptic line: Anthropic is both the AI lab and the party doing the threat analysis - their incentive structure may bias the severity framing upward, and the 832 accounts are a self-selected subset of total bans.

🧭 Where this goes

  1. LikelyMITRE ATT&CK gets an update within 12 months to include agentic AI attack categories, driven by Anthropic and partners like Verizon.
  2. Likely'Post-compromise AI assist' becomes its own threat category in enterprise security tooling and SOC playbooks.
  3. PossibleAI model providers are required to submit red-team datasets to a shared government threat repository as part of voluntary safety frameworks.
  4. Wild CardA major public breach is traced directly to an AI-orchestrated lateral movement attack that all MITRE-based tools flagged as low risk - triggering regulatory action on framework standards.

🥄 The Spoon Take

What's interesting: the old signal was simple — sophisticated attackers used more techniques. AI breaks that signal. Skill level and technique count no longer correlate. What separates dangerous actors now is whether they've wired AI into the post-compromise chain, and no mainstream security tool measures that yet.

🤔 Pushback

Anthropic is both the model provider and the threat analyst here, so they have incentive to emphasize AI-enabled danger; the doubling comes from a self-selected sample.