Evidence over alarm
+ A FIELD GUIDE TO AI & CYBERSECURITY

AI is doing more
of the attack.

This is moving beyond better scam emails.

In reported cases, AI has helped steal information, carry out intrusions, and coordinate work. See what changed—and what it means in the real world.

Understand the change
16 documented cases · 2024–2026 · No technical background needed.FOLLOW THE EVIDENCE
THE CHANGING DIVISION OF WORK

From assistance
to action.

BROADER ROLE FOR AI IN THESE CASESSelected disclosures · Human-directed campaigns
2026

More cases.
Different settings.

Parallel espionage. Tests crossing into real systems.

Malicious useAgents support parallel espionage Evaluation incidentA test reaches real systems Later examples, not a scored increase in autonomy.
Read upward as a broader role, not a higher attack count. Heights and spacing are schematic.How to read this ↗
STEP 03 / A REAL CASE

AI coordinates an espionage campaign

Read the case
A PERSONSets goals & approves
AI DOES THE WORK
Agent 1
Agent 2
Agent 3
A sequence of tasks, divided up
Some real intrusions
ILLUSTRATION OF THE MECHANISM · NOT A COUNT OF ACTUAL AGENTS
80–90%

of the hands-on work
delegated to AI

IN THIS REPORTED CAMPAIGN

Anthropic’s estimate for this campaign, not a success rate or a global average. Anthropic

WHAT AI DID

Groups of AI agents carry out much of the operational work between human decisions.

WHAT PEOPLE STILL DID

People select targets and approve important transitions.

WHAT ACTUALLY HAPPENED

Anthropic reported a handful of successful intrusions among roughly 30 targets. AI also made errors and overstated some findings.

Anthropic

The change: The human role can shift from doing each task to directing and checking the operation.

03 / 03

These are selected examples, not first-ever claims or a measurement of worldwide attack growth. Dates mark disclosure. Read the evidence and limits.

01 / WHAT THIS MEANS OUTSIDE THE LAB

Not just a smarter chatbot.
Consequences people recognize.

You don’t have to use AI to be affected. The relevant questions are what it can reach, what it can do, and whose information is on the other side.

FOR PEOPLE

Private information can leave the building.

Student and citizen information was reportedly stolen in the parallel-agent espionage case. Anthropic

You do not have to use an AI product for an AI-assisted attack to affect information about you.

See what happened
FOR ORGANIZATIONS

Your supplier’s problem can become yours.

Anthropic described a vendor breach with roughly 200 downstream organizations affected. Anthropic

An organization can inherit exposure through a service or supplier it trusts.

See what happened
A DIFFERENT KIND OF INCIDENT

A test reached someone else’s real systems.

OpenAI reported unauthorized code running on 41 Hugging Face server workers during an evaluation incident. OpenAI

This was a testing failure with reduced safeguards, not a malicious customer campaign. It still had real consequences.

See what happened
02 / TAKE IT INTO YOUR WORLD

What should I take
from all this?

The useful wake-up call is a change in the questions we ask.

You don’t need to understand the code.

  1. Ask what actually happened.

    Was information stolen, a service interrupted, or an attempt stopped? Those are different outcomes.

  2. Ask what AI contributed.

    Writing a message, carrying out a task, and coordinating agents are different kinds of involvement.

  3. Ask whose evidence this is.

    A provider’s investigation is useful evidence. Look for what an affected organization or independent reviewer also found.

A useful headline tells you the action, the outcome, and who reported it.

TURN AWARENESS INTO ACTION

What should your organization do?

Explore five areas to protect, the technology that can help, and the evidence to ask for.

The AI security framework

Take this seriously.
Keep the claims specific.

These cases establish real misuse and real failures. They do not tell us how common every behavior is, or that every model can reproduce it. Defenders are also using AI, and several of these operations were disrupted.

Our approach
THE UNDERLYING RECORD

Explore the full chronology.

16 cases. Two clocks: when activity happened, and when it became public.

Open tracker
+ THE INCIDENT TRACKER
A living record · Updated Sep 11, 2026
THE PUBLIC RECORD

A clearer picture,
one incident at a time.

16documented cases
in this collection
2024–2026
FEB 24MAR 24APR 24MAY 24JUN 24JUL 24AUG 24SEP 24OCT 24NOV 24DEC 24JAN 25FEB 25MAR 25APR 25MAY 25JUN 25JUL 25AUG 25SEP 25OCT 25NOV 25DEC 25JAN 26FEB 26MAR 26APR 26MAY 26JUN 26JUL 26AUG 26SEP 26
Evaluation incidentMalicious useAI as a targetRelated fraud

Each dot is one case. Dates show public disclosure, not when an attack began. Most September cases were published together in one report.

SELECT A DOT

Explore the story behind a case.

A collection of documented cases, not a global attack counter or a measure of growth.How we count
TRANSLATE THE HEADLINES

A little understanding
goes a long way.

Short, shareable explanations of the mechanisms behind the stories.