A 40-minute window on PyPI. A session cookie sitting in memory on a server that had done nothing wrong. A phone call that lasted a few minutes. None of these needed a sophisticated attacker. All of them needed exactly one thing: a credential that was real, valid, and reachable, at the moment someone or something went looking for it.

Thirteen incidents, late 2025 through August 2026. Different entry points. Same failure underneath.

When The Attack Ran Itself

Anthropic disclosed in November 2025 that a Chinese state-sponsored group had weaponized Claude Code and the Model Context Protocol to run cyber espionage against roughly 30 organizations. The AI executed 80 to 90 percent of tactical operations independently, at request rates Anthropic itself describes as physically impossible for a human to sustain. Human involvement came down to four to six approvals per campaign. Anthropic called it a watershed moment. It predates most of what follows by nine months, and it's the baseline everything else builds on.

Sysdig documented something similar in July 2026: JADEPUFFER, the first confirmed case of an AI agent running a full ransomware lifecycle end to end, no human directing the intrusion itself. Access, credential theft, lateral movement, database extortion, the ransom note. The agent went from a failed login to a working exploit in 31 seconds.