+ A FIELD GUIDE TO AI & CYBERSECURITY
AI is doing more of the attack. This is moving beyond better scam emails.
In reported cases, AI has helped steal information, carry out intrusions, and coordinate work. See what changed—and what it means in the real world.
Understand the change
THE CHANGING DIVISION OF WORK
From assistance to action. Save this visual BROADER ROLE FOR AI IN THESE CASESSelected disclosures · Human-directed campaigns
FEB 2024 01 Assist Help with a task Research. Draft. Write code. EXPLORE THIS STEP ↗ AUG 2025 02 Execute Help carry out an attack Move from advice to action. EXPLORE THIS STEP ↗ NOV 2025 03 Coordinate Run a chain of tasks Do more between check-ins. READING THIS STEP ↗
Read upward as a broader role, not a higher attack count. Heights and spacing are schematic. How to read this ↗
STEP 01 / A REAL CASE
AI helps prepare deceptive emails Read the case → AI DOES THE WORK Research + a draft A single requested task → Material for a person to use ILLUSTRATION OF THE MECHANISM · NOT A COUNT OF ACTUAL AGENTS
WHAT AI DID Helps research people, draft text, and work on basic code.
WHAT PEOPLE STILL DID A person directs the work and decides what to do with the answer.
The change: The same kinds of help used in ordinary office work can also assist an attacker.
← 01 / 03 →
STEP 02 / A REAL CASE
An AI operator for data extortion Read the case A PERSON Directs the attack → AI DOES THE WORK Actions + analysis Parts of an intrusion → ILLUSTRATION OF THE MECHANISM · NOT A COUNT OF ACTUAL AGENTS
WHAT AI DID Assists with intrusions, handling stolen data, and extortion demands.
WHAT PEOPLE STILL DID An operator directs the criminal campaign.
WHAT ACTUALLY HAPPENED Anthropic reported data theft and demands for payment. A demand is not proof that a victim paid.
Anthropic ↗ The change: AI can support the work between finding a target and pressuring a victim.
← 02 / 03 →
STEP 03 / A REAL CASE
AI coordinates an espionage campaign Read the case A PERSON Sets goals & approves → AI DOES THE WORK A sequence of tasks, divided up → ILLUSTRATION OF THE MECHANISM · NOT A COUNT OF ACTUAL AGENTS
80–90% of the hands-on work delegated to AI
IN THIS REPORTED CAMPAIGN
Anthropic’s estimate for this campaign, not a success rate or a global average. Anthropic ↗
WHAT AI DID Groups of AI agents carry out much of the operational work between human decisions.
WHAT PEOPLE STILL DID People select targets and approve important transitions.
WHAT ACTUALLY HAPPENED Anthropic reported a handful of successful intrusions among roughly 30 targets. AI also made errors and overstated some findings.
Anthropic ↗ The change: The human role can shift from doing each task to directing and checking the operation.
← 03 / 03 →
01 / WHAT THIS MEANS OUTSIDE THE LAB Not just a smarter chatbot. Consequences people recognize. You don’t have to use AI to be affected. The relevant questions are what it can reach, what it can do, and whose information is on the other side.
FOR PEOPLE Private information can leave the building. Student and citizen information was reportedly stolen in the parallel-agent espionage case. Anthropic ↗
You do not have to use an AI product for an AI-assisted attack to affect information about you.
See what happened FOR ORGANIZATIONS Your supplier’s problem can become yours. Anthropic described a vendor breach with roughly 200 downstream organizations affected. Anthropic ↗
An organization can inherit exposure through a service or supplier it trusts.
See what happened A DIFFERENT KIND OF INCIDENT A test reached someone else’s real systems. OpenAI reported unauthorized code running on 41 Hugging Face server workers during an evaluation incident. OpenAI ↗
This was a testing failure with reduced safeguards, not a malicious customer campaign. It still had real consequences.
See what happened
02 / TAKE IT INTO YOUR WORLD What should I take from all this? The useful wake-up call is a change in the questions we ask.
I’m a curious reader I lead an organization I report on these stories
You don’t need to understand the code. Ask what actually happened. Was information stolen, a service interrupted, or an attempt stopped? Those are different outcomes.
Ask what AI contributed. Writing a message, carrying out a task, and coordinating agents are different kinds of involvement.
Ask whose evidence this is. A provider’s investigation is useful evidence. Look for what an affected organization or independent reviewer also found.
A useful headline tells you the action, the outcome, and who reported it.
Make it a concrete boardroom conversation. What can our AI systems reach? Which data, services, and actions are available to them, including through suppliers?
Where does a person have to approve? Which consequential actions require a human decision, and can the system continue if that check fails?
How would we detect and stop a mistake? Who owns monitoring, containment, and the decision to pause an AI workflow?
These are discussion prompts grounded in the cases, not a complete security assessment.
Make the claim as specific as the evidence. Separate capability from frequency. A new kind of behavior does not establish that attacks are doubling, or that every attacker can reproduce it.
Name the denominator. Targets, confirmed victims, agents, and affected records are not interchangeable counts.
Keep the human and the date in the story. Who directed the activity? When did it happen? A disclosure date may be months later.
Every case links back to original reporting and labels the gaps in what is known.
TURN AWARENESS INTO ACTION What should your organization do? Explore five areas to protect, the technology that can help, and the evidence to ask for.
The AI security framework Take this seriously. Keep the claims specific. These cases establish real misuse and real failures. They do not tell us how common every behavior is, or that every model can reproduce it. Defenders are also using AI, and several of these operations were disrupted.
Our approach
THE UNDERLYING RECORD Explore the full chronology. 16 cases. Two clocks: when activity happened, and when it became public.
Open tracker + + THE INCIDENT TRACKER
A living record · Updated Sep 11, 2026 THE PUBLIC RECORD
A clearer picture, one incident at a time. 16 documented cases in this collection
When disclosed When it happened
Save snapshot Evaluation incident Malicious use AI as a target Related fraud
Each dot is one case. Dates show public disclosure, not when an attack began. Most September cases were published together in one report.
SELECT A DOT Explore the story behind a case.
A collection of documented cases, not a global attack counter or a measure of growth.How we count ↗
03 / KEEP FOLLOWING THE EVIDENCE
Start with one story. All 16 cases A lasting reference point, alongside selected cases that help explain what is changing.
THE FLAGSHIP EXPLAINER Watch a 70-second reconstruction of the boundaries crossed, with chapter-by-chapter evidence from the investigators.
▶ Watch the visual story Evaluation incidentCASE 01
The Hugging Face intrusion During internal tests, AI agents found unauthorized ways to reach the internet, share discoveries, and break into other systems. Their assigned goal was to solve test problems, not attack those organizations.
Disclosed Jul 16, 2026 Test → real systems
SELECTED READING Makes coordinated AI work tangible: parallel agents, human direction, and reported theft of personal records.
Malicious useGTG-10007
Espionage with parallel AI agents Chinese-speaking operators coordinated AI agents for intrusion and vulnerability research. Student and citizen information was stolen.
Disclosed September 2026 Human-directed
SELECTED READING Shows prompt injection through a real consequence: a system exposing keys after reading malicious instructions.
Malicious useGTG-50020
Turning an AI evaluation against its owner Malicious instructions tricked a vendor's evaluation environment into releasing keys. Attempts to obtain an unreleased Claude model failed.
Disclosed September 2026 Human-directed
How these stories are selected Help readers choose a useful starting point, with a standing Hugging Face explainer and room for newer, reviewed cases. Placement reflects explanatory value and our coverage focus, not a ranking of damage. Source-backed OpenAI and Anthropic relationships receive preference within the same editorial priority. Media attention is not evidence of severity.
The Hugging Face intrusion Editorial review · Sep 11, 2026 Provider and affected-party technical reports, plus an independent investigation; their findings and limits remain attributed.
Espionage with parallel AI agents Editorial review · Sep 10, 2026 Anthropic’s threat report; the campaign’s reported outcomes remain source-attributed.
Turning an AI evaluation against its owner Editorial review · Sep 10, 2026 Anthropic’s threat report; key exposure is distinguished from the failed attempt to obtain an unreleased model.
“Reviewed” means checked against the cited sources; it does not imply independent confirmation of every reported event. The full library preserves cases beyond these selections.
TRANSLATE THE HEADLINES A little understanding goes a long way. Short, shareable explanations of the mechanisms behind the stories.