AI is Becoming a Core Tool in Cybercrime, Anthropic Warns
A new report from Anthropic has shed light on the growing role of artificial intelligence (AI) in cybercrime, revealing how criminals are using AI to actively run parts of their operations. The findings suggest that AI has become embedded across the full attack cycle, from reconnaissance and malware development to fraud and extortion.
Targets of the attack included hospitals, government agencies, and emergency services. Instead of using AI only for advice, the attacker gave it operational instructions, then relied on the model to make tactical and strategic choices.
The AI scanned networks, harvested credentials, built malware to avoid detection, and even analyzed stolen data to decide which ransom amounts to demand. The model also generated customized ransom notes that reflected the victim's industry, size, and regulatory exposure.
This shows that AI can collapse the gap between knowledge and execution. What once required a group of skilled operators can now be carried out by a single person directing a model.
Criminals are building AI into every stage of their work
Criminals are building AI into every stage of their work, Anthropic documented attackers using AI for reconnaissance, privilege escalation, malware obfuscation, data theft, and ransom negotiations.
One Chinese group was seen leveraging AI across nearly all MITRE ATT&CK tactics during a months-long campaign against Vietnamese critical infrastructure. The model served as a code developer, security analyst, and operational consultant throughout.
The use of AI in so many phases creates two problems for defenders
The use of AI in so many phases creates two problems for defenders. First, attacks can move much faster, since AI removes manual bottlenecks. Second, AI-driven operations adapt quickly to defensive measures.
Traditional assumptions that complex attacks require advanced operator skill are breaking down. A single actor with average skills can now orchestrate campaigns that look like the work of a well-funded team.
AI is Transforming Fraud
Beyond technical intrusions, the report highlights how AI is transforming fraud. Criminals are using models to analyze stolen data, build victim profiles, and run fraudulent services.
Anthropic found cases where AI powered carding platforms, romance scams, and synthetic identity operations. For example, one actor used AI to process massive amounts of stolen log data, turning it into behavioral profiles of victims.
The report also highlights how AI is creating fraud ecosystems that are more scalable, adaptive, and profitable. The tools allow criminals to offer services that look professional and reliable to other actors, while hiding the fact that their technical knowledge may be limited.