Attackers Use AI to Rank What to Steal

Gambit Security says multiple threat actors have started using AI inside real intrusions to write code, harvest credentials, and sort through victim networks. In one case, a suspected ransomware operator used Claude Code during June 2026 intrusions against six organizations, including an Australian energy utility and firms in finance, manufacturing, and IT services. The model did more than autocomplete prompts: it processed reconnaissance output, pointed to domain controllers, file servers, backup servers, and the databases that mattered most, then helped stage database dumps for exfiltration. In one incident it copied a dump to the operator’s machine and deleted it from the victim server, which turns the AI into a speed-up for theft and persistence, not just a novelty tool. For defenders, the shift is that access alone can now be converted into selective theft faster and with less human effort. If your environment allows AI assistants on admin or analyst systems, the trust boundary now includes the tool’s ability to interpret logs, inventories, and terminal output in ways that help an intruder choose the highest-value targets first.

Part of the PlainSec briefing for 2026-08-19

Editions

Sources