DevSecOps

Anthropic Says AI Is Making Cybercrime Easier: Here's How to Respond

The Anthropic report of August 2025 on how AI lowers the barrier to entry for cyberattacks, and what it means for defence.

October 6, 20257 min
Arturo D.
Adservio Expert
Anthropic Says AI Is Making Cybercrime Easier: Here's How to Respond
TL;DR
  • An Anthropic report (August 2025) shows that AI, via Claude, was hijacked to build "no-code" ransomware and intensify data extortion campaigns.
  • AI mainly widens the pool of cybercriminals: attacks that once required deep technical expertise are now within reach of less experienced individuals.
  • Facing attackers who collaborate and share AI tooling, isolated defense is no longer enough: cross-sector collaboration between AI vendors, cloud providers, and cybersecurity firms is required.
  • Time-tested security practices (security by design, continuous testing) remain valid and must be combined with defensive AI, not replaced by it.
  • Five priority actions are identified: countering social engineering, accelerating identity investments, hardening high-value endpoints, AI-assisted red teaming, and faster detection and response.

Introduction

In late August 2025, Anthropic published a report demonstrating how AI is rapidly transforming the threat landscape. It highlights how the technology lowers the barrier to entry for sophisticated cyberattacks and exposes how the organization's flagship LLM, Claude, is being used to create and sell "no-code" ransomware and to intensify data extortion campaigns.

To some extent, Anthropic's report simply underscores what was already becoming clear earlier this year. Security firm Palo Alto published a report in July showing how the Scattered Spider criminal group exploits AI in its operations, using everything from deepfake voice audio to manipulate support staff to AI-powered tools for network navigation and lateral movement.

But what is particularly striking about Anthropic's report is that it shows AI is expanding the pool of cybercriminal talent. Attacks that would once have required considerable technical expertise, like scripting basic malware, are now within reach of less experienced individuals.

So if cybercriminals can now do more with less, what can organizations do about it? Yes, AI will make up a significant part of the solution, but, as we will lay out in this article, it will also mean leveraging long-proven security practices and principles.

The importance of collaborative defense against AI-driven cybercrime

An essential first step is strengthening internal cybersecurity capabilities. This means investing in talent, whether through hiring or through growth and training opportunities for engineering staff.

But beyond that, it's also important to remember that defending in isolation will likely be a losing strategy, particularly in an ecosystem where attackers collaborate and share AI-powered tools.

From individual resilience to collective defense

After all, the threat landscape is evolving faster than any single organization can manage alone. This calls for a shift from individual resilience to collective defense. Yes, governments can and will set boundaries through legislation, but AI technology is moving too fast for lawmakers to keep pace. Waiting won't work: real resilience and effective security will come from a new level of self-governance and collaboration.

Cross-sector alliances between AI vendors, cloud providers, and cybersecurity firms are essential to raise the cost of abuse for attackers. Public-private partnerships must extend beyond advisory boards to build global, scalable defenses that match the speed of AI-powered threats.

Security by design and shared accountability

At the organizational level, meanwhile, only by building security into the conversation from the start, at the design and development stages, will we have a real chance of making the right changes, faster.

This shared responsibility extends to the builders and users of these systems. We need clear accountability to answer the hard question: who is responsible when something goes wrong? In this new era, balancing innovation and security is not just a technical challenge; it's how we build the trust needed to succeed.

AI agents shouldn't be a security nightmare
Related readAI agents shouldn't be a security nightmarePrompt injection, data exfiltration, rogue agents: a six-layer framework to deploy AI agents safely in production, from least privilege to the kill switch.Read the article

A new kind of preparedness is required

This doesn't mean the old playbook is obsolete: this is certainly not the moment to panic and discard decades of good security practices. In fact, it is vital to embrace the lessons of the past and build on the practices and principles that have served us well over the past decades, like building security in from the start and rigorous, continuous testing.

Building on what we know while mobilizing AI

However, embracing good practices doesn't mean the battle has to remain asymmetric. The key is to build on what we know while also mobilizing AI to anticipate and counter cybercriminals. Indeed, failing to leverage AI opportunities can leave companies and other organizations at a permanent disadvantage, which could ultimately have significant reputational and commercial consequences.

What to do

Talking about these new risks is all well and good, you might think, but what can we actually do? While flexibility and adaptation are essential, there are a number of important steps technology leaders can take now.

Facing the rapid evolution of AI-assisted threats, organizations must adopt a multilayered defense strategy that combines human vigilance with advanced technologies. The following five priority action areas form the foundation of a resilient security posture in the AI era.

Priorities 1 and 2: social engineering and identity

Recognize that social engineering is the primary breach vector. AI can do sophisticated things, but it is particularly effective at powering some very basic social engineering techniques, like crafting convincing emails and replicating other people's voices. Make sure your end-user training and awareness keep pace with what's happening in the world, and continue investing in technical controls like multi-factor authentication and sophisticated detection and response engineering.

Accelerate identity investments. Identity has been called the new perimeter in cybersecurity; it's often the first place an AI-assisted threat will probe. This means organizations must, above all, treat every human, service, and AI agent as an identity that can be impersonated. Move to phishing-resistant MFA, continuous risk-based authorization, and just-in-time provisioning for privileged access. Doing so, even perfect AI deepfakes will be stopped before they can impact your business.

Priorities 3 to 5: endpoints, offensive testing, and detection

Harden your high-value endpoints. Attacks on user endpoints, laptops, and publicly exposed servers are likely to become more relentless as AI costs drop and adoption rises. Prioritize patching, hardening, strong network visibility, and device assurance controls. At the same time, targeted defenses, like endpoints used by platform engineering or data teams, which may have elevated access to sensitive data, should be protected as a priority.

Find the vulnerabilities before the adversary does. Adopt AI-assisted red team tactics to find weaknesses in your infrastructure. Bringing AI into the equation can not only strengthen your security posture but also help you manage the costs of what can sometimes be expensive work. Staying on top of threat intelligence and frequently updating your threat models will need to become the norm.

Accelerate detection and response. The only realistic way to protect against advanced threats is through an approach that balances protection with detection, response, and recovery. Some organizations focus too heavily on protective controls because legacy technologies and established ways of working make it difficult to modernize their security approach. The good news is that AI-assisted approaches can support you with proactive threat hunting and targeted modernization.

DevSecOps: 10 best practices for building security in from the start
Related readDevSecOps: 10 best practices for building security in from the startTen DevSecOps best practices to build security into your CI/CD pipeline: SAST, DAST, software supply chain, hardened containers and a shared culture in 2026.Read the article

It's not just an AI arms race: it's also about process and practice

The AI genie is out of the bottle. Both sides of the firewall are armed. What will separate tomorrow's breach headlines from footnotes won't be who owns the smartest algorithm or the most expensive AI tooling, it will be who can mobilize AI around sensible, measurable safeguards faster than the adversary can weaponize the latest trick.

Disclaimer: The statements and opinions expressed in this article are those of the author(s) and do not necessarily reflect the positions of Adservio.

AICloudSecurityDataTesting

GET THIS ARTICLE

Download the full article as a PDF to read offline or share it.

SHARE THIS ARTICLE

On LinkedIn, X or by email, or just copy the link.

STAY POSTED

Get our next analyses and field notes straight to your inbox.

TALK TO AN EXPERT

Put these ideas into practice

Talk to our engineers about how this applies to your platform, your data and your teams.

By submitting this form, you agree to our privacy policy.

Frequently Asked Questions

Published in late August 2025, it shows that the Claude LLM was hijacked to create and sell "no-code" ransomware and to intensify data extortion campaigns, confirming that AI lowers the barrier to entry for sophisticated attacks.

The threat landscape is evolving faster than any single organization can handle alone, and attackers collaborate by sharing AI tools. Real resilience requires alliances between AI vendors, cloud providers, and cybersecurity firms, beyond mere advisory boards.

Five priorities: strengthen training against social engineering (convincing emails, cloned voices), accelerate identity investments (phishing-resistant MFA, continuous authorization), harden high-value endpoints, run AI-assisted red teaming to find vulnerabilities first, and accelerate incident detection and response.