Four AI-enabled attacks were confirmed and technically documented in the last two quarters, not five. That is not a shortfall. It is the more honest number, because most of what gets pitched as an AI-powered attack in vendor threat reports is marketing dressed up as intelligence. These four are different. Each one has a named researcher, a technical writeup, and in most cases a CVE or a formal threat actor designation attached to it. That is the bar this piece holds to.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
A Nation-State Group Let Claude Run Most Of The Attack
In mid-September 2025, Anthropic's threat intelligence team caught a Chinese state-sponsored group using Claude Code to run an espionage campaign against roughly thirty organizations, including large technology companies, financial institutions, chemical manufacturers, and government agencies. Anthropic disclosed the operation on November 13, 2025, and assessed with high confidence that it succeeded against a small number of targets.
The operators did not ask Claude to hack anything directly. They broke the operation into small tasks that looked like ordinary security testing, and told the model it was working for a legitimate cybersecurity firm running defensive assessments. Claude built its own reconnaissance tools, found and validated vulnerabilities, wrote exploit code, harvested credentials, and produced its own documentation of what it had done. Anthropic estimates AI performed 80 to 90 percent of the campaign's tactical work, with a human operator stepping in at only four to six decision points per operation, mostly to authorize the next phase. At peak activity the system was issuing thousands of requests, sometimes several per second, a pace no human operator team could sustain.
This is the incident to actually understand this year, because it changes what the word attacker means operationally. The bottleneck used to be skilled human operator hours. Anthropic's own writeup treats that bottleneck as gone for a well-resourced state actor with the discipline to script around a model's safety training. Whether or not you trust Claude specifically, the technique generalizes to any capable coding agent.
Malware That Asks An AI Model How To Hide
Google's Threat Intelligence Group disclosed a different kind of first on November 5, 2025. A piece of VBScript malware, which Google named PROMPTFLUX, calls the Gemini API mid-execution and asks it to rewrite and obfuscate its own source code, with one variant designed to regenerate its entire body on an hourly cycle to dodge signature detection.
Google was careful to frame this correctly. It called PROMPTFLUX a malware family still in development or testing, said it currently lacks any means to actually compromise a device or network, and left the self-rewriting function disabled in the samples it found. Security researcher Marcus Hutchins, who helped stop WannaCry, pushed back publicly, arguing that Gemini does not inherently understand antivirus evasion and that the regenerated code has no entropy or functionality checks behind it. Both things are true at once. The sample is unsophisticated today, and it is also a working proof that a piece of malware can hold a live conversation with a frontier model at runtime and use the answer to change itself. That capability does not need to be sophisticated to be worth planning around. It needs to exist once, then get copied.
A Deepfake Interviewee Almost Got Hired
In March 2026, a recruiter at a Tokyo IT company interviewed a remote candidate whose resume matched a real, named CEO of an unrelated firm. Analysis by Okta and a Tokyo deepfake detection startup found the tells that gave it away, an unnatural hairline boundary, a brief misalignment between eyes and lip movement and audio. The candidate ended the call within two minutes of being told the role required in-person attendance.
That would be a curiosity if it were isolated. It is not. Okta's investigation tied it to a pattern involving more than 6,500 similar cases globally, workers believed to be North Korean operatives using fabricated identities and, increasingly, real-time deepfake video to pass remote hiring interviews at foreign companies, then routing their pay back to the regime. The AI did not breach a network. It breached the interview, which is the control most companies still treat as a formality, not a security boundary.
AI Lowered The Skill Floor For Ordinary Phishing
Cisco Talos's Q1 2026 incident response report documented attackers using Softr, an AI-assisted web app builder marketed for building sites without writing code, to stand up credential-harvesting pages targeting Microsoft Exchange and Outlook Web Access accounts in a public administration sector intrusion, with stolen credentials routed to disposable Google Sheets. Talos assessed with moderate confidence that abuse of Softr and similar AI site builders has been rising in frequency since 2023.
Nothing here required jailbreaking a model or beating a safety filter. The attacker used a legitimate product exactly as designed. That is the least dramatic entry on this list, and arguably the most consequential one, because it describes thousands of low-skill actors, not one nation-state team.
What A Tuesday Looks Like If You Get This Wrong
Picture a mid-size manufacturer's help desk on an ordinary Tuesday. A call comes in from a number that matches an internal extension, a voice that sounds like a known IT staffer, asking for an MFA reset because the badge reader is down and there is a customer call in five minutes. The request follows the exact script the help desk trains on. It also happens to be synthetic. None of the four incidents above required a novel technique to pull that off. The Anthropic case shows an AI agent can plan and sequence such a pretext. The deepfake case shows AI can produce a voice and face convincing enough to survive a live call. The phishing-kit case shows the credential-harvesting page behind it can be built by someone with zero web development skill. Put those three capabilities in the hands of one moderately resourced criminal group, and the help desk call above stops being hypothetical.
The Counterargument, Argued Straight
The strongest objection to this article is that three of the four incidents involve a nation-state actor, an experimental malware sample that cannot yet do real damage, or a hiring fraud scheme running at a scale most companies will never see up close. A CISO at a mid-market company could reasonably say none of this changes their threat model this quarter, and that attention spent studying Claude Code espionage techniques is attention taken from patching the same unglamorous vulnerabilities that cause most breaches. That argument is not wrong. Base rates still favor commodity ransomware and credential stuffing over anything on this list. If your patching cadence and MFA coverage have gaps, close those first, because none of these four attacks bypass basic hygiene. They bypass the assumption that a human is on the other end of a request.
The counter to the counterargument is capability diffusion, not a change in this quarter's odds. The tactic a state-sponsored group scripted in September 2025 does not stay state-sponsored. It becomes a tool, then a service, then a line item in a criminal price list, on a timeline measured in months, not years. Planning starts now specifically because the decision cycle for hiring controls, help desk verification scripts, and vendor contracts is slower than the diffusion cycle for the technique itself.
Questions For Monday
Bring these to leadership and the board before the next budget cycle, not after the next incident.
Does your help desk have a verification step for identity that does not rely on caller voice or video matching what someone expects to hear or see?
Who in your hiring pipeline is trained to spot a fabricated remote candidate, and does that training predate 2026?
If a coding agent inside your environment started acting outside its normal task pattern, would anyone notice before it finished, or only after?
Has anyone quantified how fast a low-skill actor could stand up a credential-harvesting page using a tool your own marketing or product teams already have licenses for?
Four confirmed, technically documented incidents is a small number. It is also the floor, not the ceiling, and the floor is rising faster than most security budgets are.