Anthropic August 2025 threat report described operation GTG-2002, where a single criminal used an AI coding agent to automate the full attack chain, reconnaissance through ransom-note generation, against at least 17 organizations including healthcare, emergency services and government. The actor even used the model to analyze stolen financial data and set ransom amounts, some over half a million dollars. The AI was not a coding assistant here. It was the operator.
This is the threat the industry talked about in the abstract, now documented in the concrete. One person with a model did the work that used to require a crew.
The defensive lesson is unglamorous. AI lowers the cost of attacker labor, so the controls that survive are the ones that do not depend on attacker effort being expensive: MFA everywhere, segmentation, least privilege, and detection that does not care how the intrusion was authored.