Anthropic's September 2026 threat-intelligence report covers malicious Claude use it disrupted from December 2025 through August 2026. That includes a Russia-aligned campaign consistent with Midnight Blizzard hitting 20+ government and defense orgs, and ShinyHunters-linked affiliates dumping roughly 2,100 Azure AD token sets across 40+ tenants in about 34 hours. Chinese-linked appliance research allegedly produced 12+ possible zero-days in a month. Reuters coverage the same week also cited Anthropic accusing Chinese labs (including Alibaba-linked activity) of illicit model distillation peaking near 3 million exchanges/day from 3,500+ fraudulent accounts (May–July 2026).

You do not need to be a Fortune 50 target for the pattern to matter. Device-code phishing plus Entra token theft is already a high-probability path against Livermore Microsoft 365 tenants — and AI APIs just accelerate the recon and exfil loop once an identity is owned.

Practical move this week: inventory which staff and which bots hold AI API keys; revoke unused keys; require phishing-resistant MFA on admin and high-value accounts; and treat "the AI agent can read SharePoint" the same way you'd treat a service account with Files.Read.All.