AI agents data theft moved from an efficiency concern to an operational security warning in Anthropic’s September 2026 threat-intelligence report. In one cluster of financially motivated intrusions, the company says AI agents performed nearly all of the technical work, from reconnaissance and privilege escalation to creating tools and extracting data. Anthropic’s report, released on 10 September, describes selected misuse cases observed between December 2025 and August 2026.
The important change is economic rather than magical. The report does not describe an AI independently deciding whom to attack and how to monetise the result. Human operators still selected targets, reviewed progress and handled criminal objectives. The agents compressed the amount of human labour needed to execute familiar attack stages at speed and across multiple victims.
How AI Agents Data Theft Changed the Workload
Anthropic describes activity linked to ShinyHunters affiliates in which an operator used agents to automate large parts of intrusion and extraction workflows. The report says one technology provider had more than one terabyte of data exfiltrated, including hundreds of thousands of national-identity records and millions of payment-card records. It also describes compromises affecting airline systems, SaaS environments and cloud accounts. These are Anthropic’s reported cases, not an independently audited census of cybercrime.
One example involved a session-store dump containing 2,100 Azure AD token sets spanning more than 40 tenants, obtained within 34 hours. In another breach, Anthropic says an operator moved from initial access to cloud administration in roughly three hours. The company argues that agents were useful because they could interpret APIs, write and modify tools, automate bulk exports and continue working through multi-step technical tasks.
That pattern fits the concern raised in LiveAIWire’s coverage of the Five Eyes warning on AI-enabled cyberattacks. The threat is not necessarily a new class of exploit. It is the possibility that one capable operator can handle more targets, more data and more technical steps than would previously have been practical.
Nearly All the Technical Work Does Not Mean Fully Autonomous Crime
The phrase “nearly all the work” needs a boundary. Anthropic says agents carried out most of the technical execution in the highlighted operations, but humans remained responsible for target selection, monetisation and high-level review. That distinction matters because autonomy and harm are not the same thing. A human-directed agent can create serious damage even if it never chooses the objective itself.
Anthropic also says the published cases are notable examples rather than typical misuse across its service. The company is reporting what it observed on its own systems and the actions it took to disrupt that activity. Victims are largely unnamed, and the underlying evidence has not been independently audited. The report should therefore be read as a first-party threat-intelligence account, not a universal measurement of how cybercriminals now operate.
What This Means for Security Teams
Defenders should pay attention to speed. Traditional incident response often assumes that discovery, reconnaissance, lateral movement and data collection create windows in which unusual activity can be detected. If an agent can compress several of those steps into hours, monitoring and access controls have less time to interrupt the chain.
The report also strengthens the case for least-privilege access and short-lived credentials. If an attacker gains a valid token or account, an agent can potentially enumerate resources and exploit permitted interfaces rapidly. Strong identity controls become more important when the cost of exploring a compromised environment falls.
LiveAIWire’s earlier report on AI-assisted hacking against Taiwan showed how models can support cyber operations without replacing the human operator. Anthropic’s new examples push that idea further by showing agents handling longer chains of work. The practical security question is no longer simply whether criminals use AI. It is how much of the attack cycle one person can delegate.
Agentic Cybersecurity Cuts Both Ways
The same capability can be used defensively. Security teams can employ agents to investigate alerts, correlate logs, test configurations and accelerate remediation. The challenge is that both sides benefit from automation. A defender does not gain a permanent advantage merely by deploying similar tools.
That is why control architecture matters. LiveAIWire has covered experiments in which AI agents sabotaged one another under adversarial incentives. Those tests were different from live cybercrime, but they underline the need to constrain what an agent can reach, record what it does and avoid assuming that useful autonomy is automatically safe autonomy.
The Cybercrime Bottleneck Is Moving
Cyberattacks have always been constrained by some combination of access, expertise, time and coordination. Anthropic’s report suggests that agents can reduce the labour component. That does not make every attacker highly skilled, and it does not eliminate the need for credentials, vulnerabilities or victims. It does mean that once access exists, the operator may be able to move faster and manage more parallel activity.
For organisations, the response is not panic about autonomous hackers. It is faster detection, tighter privileges, better credential hygiene and incident plans designed for machine-speed execution. The human criminal is still making the consequential decisions. The worrying part is that the human may now need far fewer colleagues to carry them out.
Anthropic also says some operators used stolen customer API keys to access Claude, while its own systems were not compromised. That distinction matters for organisations reviewing logs after an incident: legitimate credentials can give malicious automation a normal-looking route into tools. Protecting API keys, rotating exposed tokens and monitoring unusual usage patterns therefore become part of the same defensive problem as securing employee accounts.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity and the social impact of emerging technology. LiveAIWire is an independent, human-led technology publication using AI-assisted research, editorial production and original AI-assisted editorial illustrations under his direction.
