Anthropic's fourth threat-intelligence report (covering Dec 2025 - Aug 2026) documents AI-augmented operations across seven harm areas. GTG-50020 stole production API keys by prompt-injecting an AI vendor's evaluation sandbox, then attacked ~30 AI companies in ~4 days explicitly seeking pre-release Claude model access (never obtained; Anthropic itself not breached). Other findings: GTG-20006 (Midnight Blizzard-linked espionage) exfiltrated 300k+ identity records and a complete drone vision SDK, with AI agents autonomously rebuilding malware when security products detected it; GTG-50014 (ShinyHunters affiliates) dumped 2,100+ Azure AD token sets across 40+ tenants in ~34 hours; GTG-10007 (Changsha-based exploit foundry) ran agent swarms yielding 'more than a dozen possible zero-day findings in a single month'; fraudulent resellers proxied paying users to a different model while harvesting credentials (GTG-50021). Cross-cutting: most operations used multi-agent frameworks running unsupervised for hours or days; stolen AI credentials now have triple utility (loot, compute at victims' expense, misattribution cover); the sophistication gap has collapsed — 'the key differentiator between actor classes is now intent, not capability'.
Two operational takeaways: evaluation sandboxes are now an attack surface for model access (if you run evals on vendor APIs with production credentials, prompt injection is an exfiltration path), and stolen API keys have become infrastructure for attackers — key-per-deployment, rotation and anomaly monitoring move from hygiene to necessity. The 'intent, not capability' finding sets the baseline for threat modeling in 2026.
| Edition | 4th report (after 2025-03/08/11), covering Dec 2025 - Aug 2026, seven harm areas |
|---|---|
| Gtg 50020 | prompt-injected an AI vendor's eval sandbox to steal production API keys; attacked ~30 AI companies in ~4 days seeking pre-release Claude; not obtained; Anthropic not breached |
| Gtg 20006 | Midnight Blizzard-linked espionage: 20+ orgs targeted (governments/militaries/embassies/drone supply chain); 300k+ identity records + 500k+ company registry records exfiltrated; complete drone vision SDK stolen; agents autonomously rebuilt malware on detection |
| Gtg 50014 | ShinyHunters affiliates: 1.8M APKs scanned for secrets; 2,100+ Azure AD token sets across 40+ tenants in ~34 hours; stolen token to full cloud admin in ~3 hours |
| Gtg 10007 | Changsha-based exploit foundry: agent swarms for continuous zero-day research; 'more than a dozen possible zero-day findings in a single month'; 13 scheduled collection agents |
| Gtg 50021 | fraudulent 'discounted Claude' resellers proxying users to a different model while harvesting credentials |
| Cross Cutting | multi-agent frameworks standard, running unattended hours-days; stolen AI credentials = loot + compute + misattribution; 'the key differentiator between actor classes is now intent, not capability'; operators described as 'vibe hacking' |