Original Reddit post

Anthropic just dropped a 154-page threat intelligence report (Sept 10, 2026), and one case in it is genuinely unsettling. A lone hacktivist no team, no crew used Claude to run what used to require an entire skilled group: Built a custom scanner to find exposed API keys/passwords companies left lying around online Used one AI to orchestrate a bunch of smaller AI agents (one finding weak spots, one checking work, one reviewing findings) Found and exploited a brand-new zero-day in WordPress, building the attack in real time Broke into 14+ of 42 targeted orgs, stealing ~140,000 records in a single breach alone (donor lists, member data, political affiliations) Then used Claude to build a searchable doxxing site out of tens of millions of stolen records: type in a name, get their private info, including sensitive ID numbers It was published on the dark web to expose people tied to a specific political movement. The scary part isn’t just the breach; it’s that one person did the work of an entire team , and the real damage came from scattered stolen data being fused into something instantly searchable. If you work in security, data protection, or for any org holding sensitive personal data (political groups, newsrooms, nonprofits, unions), this is worth 10 minutes of your time. To find out more, including the 4 things orgs should actually do about it**, visit @** Latha-ai-governance and watch our latest video. We aim to spread awareness among AI professionals regarding AI Governance. Question: If one person with AI can now do the damage of a whole hacking team, are your org’s defences built for the threat of today or the threat of ten years ago? submitted by /u/Comfortable_Gene5180

Originally posted by u/Comfortable_Gene5180 on r/ArtificialInteligence