The result is a dramatic acceleration in attack speed and scale.
Anthropic said it observed breaches completed in two to three hours, while individual operators handled dozens of victims in parallel.
In one case, an attacker went from a single stolen developer token to full administrative control of a victim’s cloud environment in roughly three hours.
Another breach of an enterprise software company progressed from initial access to bulk data theft in only hours.
AI agents do much of the work
The attacks themselves don’t necessarily use previously unknown hacking techniques.
In the most autonomous cases identified by Anthropic, these systems conducted reconnaissance, exploitation and theft against several victims for hours or days with minimal human supervision.
One hacker can do the work of a team
That could change the economics of cybercrime.
Tasks that previously required teams of skilled operators can increasingly be performed by AI models running continuously and at machine speed.
Anthropic said both criminal groups and state-linked actors are adopting similar techniques.
A financially motivated hacker, hacktivist or espionage operator can use AI to build tools, execute intrusions and process stolen information at volumes that would be difficult for an individual to handle manually.
Massive amounts of data stolen
Some of the compromises Anthropic uncovered were substantial.
In one case involving a technology provider, attackers exfiltrated more than a terabyte of data, including hundreds of thousands of national identifiers and millions of payment-card records.
At an airline, threat actors accessed systems containing tens of millions of passenger records, Anthropic said.
Another supply-chain attack compromised a software provider and let attackers extract data from roughly 200 downstream customer organisations.
Humans are still choosing the targets
Anthropic cautioned that this does not mean AI has completely taken over cyberattacks.
Click Here For The Original Source.
