Anthropic has revealed a comprehensive report highlighting how various cybercriminal entities have harnessed its Claude AI models to automate cyberattack processes, develop zero-day exploits, and modify malware to evade security measures. The report covers activities detected from December 2025 to August 2026, showcasing AI's growing role in streamlining cybercrime. It indicates that even individuals or small groups can launch complex attacks that were once the domain of professional teams, thanks to automation frameworks like PentAGI. Anthropic identified these actors as Generative Threat Groups, noting that AI simplifies and accelerates every stage of an attack, from reconnaissance to data exfiltration. One of the most notable cases involves GTG-20006, a group linked to Russian state actors, which targeted European and Ukrainian government entities using Claude to autonomously execute phishing and malware operations. The group's ability to adapt and redeploy malware quickly after detection creates a new challenge for defenders, as AI reduces the cost and time of cyber operations. Another significant case involves the ShinyHunters group, which employed AI for large-scale credential harvesting and data breaches. The report further documents various cases of espionage and data theft across multiple regions. Anthropic has banned the accounts involved and enhanced its security measures, sharing information with law enforcement and industry partners. The findings emphasize the need for security teams to consider AI-driven attacks as a current threat, urging a focus on detection strategies that can keep pace with both human and AI attackers.