Security firm Gambit says attackers now treat AI as a teammate inside live intrusions, not just a shortcut for writing malware. Its report, “AI Across the Intrusion Lifecycle,” documents three operations where models helped run the hack from start to finish.
Claude Code sat at the center of one investigation. A suspected ransomware affiliate ran it through intrusions at six organizations in June 2026, with two earlier compromises also on the record. Gambit assigns medium confidence that the actor works with the Gentlemen ransomware-as-a-service outfit.
Victims turned up across five countries: an Australian energy utility, a Mauritius finance firm, businesses in South Africa, Thailand, and Malaysia, and several US organizations. The tool’s chores inside those networks ranged from drafting exploit code and malicious scripts to reshaping firewall rules, mapping the environment, and scoring which databases were worth exfiltrating.
The report lines up with Anthropic’s own study of 832 malicious accounts, where AI use showed up in all 14 MITRE ATT&CK tactics and the share of actors graded medium risk or above climbed from 33% to 56% over the period examined.