The Future of AI Security
Okta, Friday, March 13th, 2026
The Right Architecture for Securing Enterprise AI Agents
In September 2025, Anthropic detected and disrupted the first documented large-scale cyberattack executed predominantly by an AI agent. A Chinese state-sponsored group (GTG-1002) manipulated Claude Code to target approximately 30 organizations across financial services, technology, manufacturing, and government.
The AI autonomously executed 80-90% of tactical operations: reconnaissance, vulnerability discovery, exploitation, credential harvesting, lateral movement, and data exfiltration. Humans intervened only at critical strategic junctures, spending roughly 20 minutes of hands-on direction per phase. A handful of targets were successfully breached.