You Don’t Need a Team of Hackers Anymore – One Attacker With AI Is Enough

AI-powered cyber attack
A report from Anthropic documents how individual attackers now use AI to run complex cyber operations once requiring a full team - from targeting to data theft. It examines the shifting balance of power between attackers and defenders, why API keys are now critical assets, and what organizations should do next.

A report recently published by Anthropic, the company behind Claude, documents malicious uses detected on its systems between December 2025 and August 2026. Its central finding is not a new attack technique, but a deep shift in who is capable of carrying out an attack: today, one person with a laptop and a language model can execute operations that yesterday required an entire team. The question the report raises is not “will AI be used for attacks,” but how fast and how cheaply this is already happening – and what that means for the defenses you are building.

From assistant to orchestrator: what’s genuinely concerning in the report

The intuitive reaction to a report like this is to look for a new attack technique. But a close reading shows the techniques themselves are well known; what has changed is who can run them, and how quickly. In the cases the company documented, AI systems carried out nearly the entire attack chain: identifying targets, scanning systems, developing intrusion tools, stealing access, maintaining persistence, and collecting and exfiltrating data. Humans set the objective and reviewed the results, but a large share of the technical work was performed automatically – at times in parallel, across several targets simultaneously.

One example from the report illustrates this well. In a case attributed with high confidence to an actor linked to known espionage activity, the attackers ran a campaign against government, defense and diplomatic bodies using AI-driven workflows. When defensive systems detected the malware, the autonomous system modified and rebuilt it until it evaded detection. This was not a one-off maneuver by a skilled attacker, but a loop: detect, analyze, modify, try again – without a human needing to rewrite code each time. A process that once demanded significant time investment to develop a new version now happens within minutes.

When sophistication stops being a signature

One of the report’s more significant insights concerns how attackers are typically classified. For years, the working assumption was straightforward: a complex, coordinated, multi-stage operation indicates an actor with substantial resources – a nation-state, an intelligence body, or an organized criminal group. The report shows this assumption no longer holds: the same technological infrastructure and the same autonomous tools are now available to a single individual with intent and a computer.

One example from the report describes a lone actor who targeted political parties, media outlets and think tanks across Europe. He used AI to develop scanning tools, exploit security vulnerabilities, steal politically sensitive information, and even build a search engine within the stolen data. An operation of this scale once required a full team – developers, intelligence analysts, data analysts. Here, one person carried it out alone.

The practical implication: the sophistication level of an attack no longer says much about the identity of the attacker. A state actor, a criminal organization, a lone hacktivist, or a disgruntled employee can all operate similar tools today at similar levels of execution. And the relevant question for defense changes accordingly: less “how many resources does our potential attacker have,” and more “how quickly will some attacker, regardless of identity, exploit a gap we haven’t closed.”

What this means for the balance of power between attackers and defenders

Another point in the report extends beyond classic cybersecurity into the supply chain of AI itself: attackers are actively searching for model access keys and login tokens. Such access has value on the criminal market, enables attacks to run at the victim’s expense, and provides cover – the malicious activity appears to come from a legitimate customer. The report describes cases where exposed keys were found in public code and mobile applications, and a network that offered discounted access to an AI service while in practice stealing user credentials and reselling them.

This changes how organizations should think about access management. An API key for an AI service is not a minor technical detail that can be left in code or a configuration file – it can be equivalent to administrator-level access to cloud infrastructure, because it grants access to computing power and data. And this is not theoretical: in security reviews at mid-size organizations, such keys turn up repeatedly in configuration files, in code pushed to shared repositories, and even in internal correspondence – a real asset managed as if it were a minor technical detail. Every organization should treat API keys with the same level of severity it applies to production system passwords.

A reasonable objection arises here: a report like this, published by a company that builds AI, is to some extent also a marketing tool – a demonstration of the company’s own detection capabilities. There is logic to that concern, but it doesn’t change the practical conclusion: even if the report is shaped by its own emphasis, it doesn’t invent the phenomenon. Autonomous attack tools are already available in the market – through Claude, competing models, or open-source tools – and they cannot be dismissed simply because of who published the report.

How this changes enterprise defense in practice

The conclusion for a typical Israeli organization is not “we need more tools” but “we need a different working assumption.” A security, backup and business continuity plan built on the assumption that an attacker operates at human pace, learns slowly, and needs time to build a new attack tool no longer reflects reality. Planning must account for an attacker who detects a defensive response, changes approach, and tries again within minutes. That means monitoring must be continuous rather than based only on periodic checks, and 24/7 availability of someone capable of identifying and stopping abnormal activity is no longer a luxury but a baseline requirement – especially for organizations without a large internal security team.

So where do you start? Four steps that can be taken this week, without a technological overhaul:
1. Map keys and secrets: scan code, repositories and configuration files for exposed API keys – and move them into centralized secrets management.
2. Find out who is using AI within the organization: which tools are in use, who opened accounts, and what permissions and data they can access.
3. Test response speed: run one exercise measuring how long it takes from alert to action – against an attacker who returns within minutes, not days.
4. Prioritize remediation: an honest review of existing defense assumptions – which ones were built against a slow, human attacker, and what to fix first.

Anthropic’s report doesn’t describe a distant future – it describes a process already under way. The question isn’t “will we be attacked,” but how long it will take an attacker to find the gap that still exists in your organization. Anyone waiting for absolute certainty before reexamining their defenses is already falling behind the pace.

If you want to assess where your organization stands against an attacker that operates and learns at machine speed, we’re here for a conversation that examines real readiness, not just what’s on paper.
To schedule a consultation: https://odoo.tom-comp.com/r/ngF

Link to the original report:
https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf

The First Step Starts Here
Professionalism
Our primary asset lies in our human capital, delivering real-time solutions on-site. Therefore, our IT technicians undergo continuous training and certification to ensure top-quality service.
Quality Assurance and Reliability
We implement high-standard quality processes that include clear procedures, documented monitoring, extensive control systems, and thorough inspections.
Availability and Teamwork
We understand the importance of maintaining the continuous operation of our clients' computer systems. Our team ensures full availability to support you whenever needed.
Integrity and Reliability
Integrity and reliability are our guiding principles, serving as a solid foundation for productive and successful collaboration.
Data Protection
T.O.M is committed to maintaining the confidentiality of information and utilizing advanced technological means to safeguard the assets of the organization and, of course, all its clients.

IT solutions designed for your peace of mind

How can we assist you?

This site uses information collection technologies such as Cookies, including by third parties, in order to provide you with a better browsing experience as well as for statistical, profiling and marketing purposes. Continued browsing of this site constitutes your consent to this. For more information and the option to manage the use of these tools, please see our updated Privacy Policy