What happened
AI workflows fingerprinted services, built and operated phishing infrastructure, ran commands against victim systems, harvested credentials, moved laterally, organized stolen data, registered actor-controlled devices, and rebuilt detected malware.
Why it matters
Anthropic identified more than 20 organizations in planning or live operations; reported impacts included compromised hospitality vendors, mailbox theft from at least eight organizations, hundreds of gigabytes of stolen data, more than 300,000 national identity records, and registry data for over half a million companies.
Missing authorization check
No independent, victim-side authorization gate constrained stolen credential use, new device registration, mailbox export, DNS changes, or other consequential state changes.
Would PP block it?
At integrated enterprise boundaries, PP could require separate approval for device registration, privileged identity changes, mailbox bulk export, DNS mutation, or other protected actions. It would not stop the initial intrusion, malware rebuilding, reconnaissance, or data reads outside those boundaries.