What we learned mapping a year’s worth of AI-enabled cyber threats
Summary
This report examines 832 accounts banned for malicious activity between March 2025 and March 2026 to understand how AI influences cyberattacks. The study finds that threat actors are increasingly using AI for complex, post-compromise tasks like lateral movement and account discovery, leading to a significant rise in high-risk activity. Furthermore, traditional risk-assessment frameworks, such as MITRE ATT&CK, struggle to account for AI-driven autonomous orchestration, where models chain attack steps together with minimal human intervention. Consequently, the authors are collaborating with MITRE to evolve these frameworks and have implemented new safeguards in their own models to better detect and block these advanced, agentic cyber threats.
(Source:Anthropic)