
Anthropic Says One Threat Actor Used Hundreds of AI Agents to Break Into 395 Organizations in Days
Anthropic's September threat intelligence report covers nine months of disrupted misuse across seven harm areas, and the standout case is an operator who deployed hundreds of agents built on OpenAI's Codex and a DeepSeek model to exploit two PaperCut vulnerabilities, compromising 440 instances across 395 organizations in 48 countries within days of public disclosure. The report also documents surveillance tooling, drone targeting software, and biological work the company blocked. The uncomfortable takeaway is that the skill gap that once separated state-sponsored hackers from lone criminals has effectively closed, because the agents do nearly all the work.








