#22 · Briefing ·

Stolen Token Grants Rapid Cloud Control

Anthropic's latest threat report details how hackers weaponized Claude models, highlighting a rapid cloud compromise and state-linked cyber campaigns disrupted between late 2025 and mid-2026.

Full cloud control in three hours
AI-generated illustration. Full cloud control in three hours

On September 10, 2026, artificial intelligence safety provider Anthropic published its fourth major threat intelligence report. The documentation outlines a series of cyber operations that were identified and disrupted on the company's platform. Among the key technical incidents highlighted was an intrusion where unauthorized actors utilized a single stolen developer token to escalate their access, achieving full cloud administrative control in approximately three hours. Additionally, the report details how a Chinese-speaking threat group, which included two university undergraduates, coordinated complex cyber campaigns targeting approximately fifty distinct organizations. The documented activities also include a operation where a Russian state-linked cyber espionage group compromised the DNS settings of at least three hotel Wi-Fi vendors to specifically target Ukrainian officials and drone-industry personnel.

While Anthropic published these findings as an account of its internal containment successes, certain details regarding the timeline and specific capabilities remain contested. Anthropic attributes the disruption of these various cyber activities to its internal Threat Intelligence team, asserting the interventions occurred between December 2025 and August 2026. However, this specific timeframe is marked as disputed. Furthermore, the report claims that the Russian-linked espionage group utilized artificial intelligence to autonomously rewrite its malware to bypass antivirus detection, a point that is also disputed. Similarly, the assertion that a French-speaking hacktivist built a search platform to expose individuals affiliated with a political movement by cross-referencing tens of millions of breached records is contested.

These findings are significant because they demonstrate how threat actors are actively attempting to leverage commercial artificial intelligence systems to accelerate and scale their operations. According to the supported claims, almost all of the documented misuse involved Anthropic's primary model families, specifically Haiku, Sonnet, or Opus. The rapid escalation from a stolen developer token to full cloud administrative control within three hours underscores the critical vulnerabilities present in modern cloud infrastructure when credentials are compromised. For organizations relying on these systems, the speed of such intrusions highlights the necessity of robust identity and access management, as well as immediate anomaly detection.

Outside observers and summarizing publishers have noted these developments but have not been able to validate the claims externally. Because the findings represent only what Anthropic caught on its own platform, the summarizing publishers have not independently verified the assertions. Additionally, security researchers have pointed out that they cannot always determine the real-world success or the ultimate reach of these disrupted campaigns, leaving the true efficacy of the threat actors' efforts partially obscured.

Several critical elements of these cyber operations remain unknown or unconfirmed. It is still unclear whether the threat actors achieved their ultimate objectives before Anthropic intervened, as the real-world success of the disrupted campaigns cannot be fully verified. Furthermore, Anthropic did not independently confirm certain attacker claims, such as the assertion that operators had successfully demonstrated remote control over residential electric vehicle charging currents. Finally, because these observations are limited to telemetry captured within Anthropic's proprietary ecosystem, the full global scale of similar AI-assisted cyber campaigns across other platforms remains undetermined.

Sources

Verified claims

Stills

What is still unknown
AI-generated. What is still unknown

Original reporting: https://www.anthropic.com/news/detecting-and-countering-misuse-of-ai-september-2026

Written by The Quiet Search. Method: /about.

Related

Comments

Plain text only. New comments stay hidden until a person reviews them.