ZENTARA

What Anthropic's September 2026 Threat Report Changes for Indonesian Security Operations

Anthropic’s September 2026 threat report reveals a drastic shift in attack velocity, showing how AI agents now drive intrusions from stolen dev keys to full cloud admin access in under 3 hours, requiring immediate updates to Indonesian security operations.

Zentara Team5 min read
What Anthropic's September 2026 Threat Report Changes for Indonesian Security Operations

What Anthropic's September 2026 Threat Report Changes for Indonesian Security Operations

Author: Trimikha Valentius (CAIO, Head of Zentara Labs), Marsha Widagdo (Head of Blue Team / SOC)

An adversary moving from a single stolen developer token to full cloud admin control in three hours isn’t a hypothetical stress test. It is the documented baseline of today’s AI-augmented operations.

Anthropic published its fourth threat intelligence report on 10th of September 2026, covering operations it disrupted between December 2025 and August 2026 across seven harm areas. None of the intrusions it documents used a technique Indonesian defenders have not seen before. Stolen credentials. Unpatched edge devices. Exposed services. SQL injection. Phishing. The attacks are familiar

What changed is the cost of running them. Anthrophic’s own framing is that the economics shifted, not the tradecraft. One documented breach moved from single stolen developer token to full administrative control of a victim’s cloud environment in roughly three hours. Another operator dumped over 2k Azure AD token sets across more than 40 corporate tenants in about 34 hours, with AI agents performing nearly all of the work.

This article sets out four findings from the report with direct Indonesian exposure, identifies where the local control regime does not engage the threat, and lists four changes worth making this quarter.

Four findings with Indonesian exposure

The Four findings below share one property. Each describes a capability that used to require a funded team and now runs from a single operator with a laptop and stolen key. The techniques are ordinary. The throughput is not. A scanning pipeline that processes 1.8 million applications, a persona farm sustaining 2.36 million conversations in a fortnight, and a firmware research loop producing a dozen candidate zero-days a month are the same shift measure in different units.

For Indonesia, none of these open a new exposure. They raise the yield on exposure that already exists. An Android-first application estate, a civil registry with a leak history, perimeter appliances running several patch cycles behind, and a population already targeted by fraud actors were all risks before this report was published. What changed is how cheaply each can now be worked, and how fast. Findings 1 and 2 are the ones most Indonesian organizations can act on directly this quarter.

#

Finding

Report evidence

Indonesian exposure

Most affected

1

Mobile apps as a credential supply chain

1.8M Android APKs decompiled and scanned for hardcoded secrets. Findings routed to Telegram in real time.

Android-first app estate on short release cycles. Secret scanning runs against source, not release builds.

Fintech, banking, e-commerce, govtech

2

AI credentials as an asset class

Stolen keys give resale value, free attack compute, and attribution cover. Fraudulent resellers harvest customer credentials.

Price sensitivity drives use of discount intermediaries. AI keys issued with no inventory, rotation, or logging.

All sectors running AI in production

3

Regional government entities targeted

Two actors hit Southeast Asian government bodies: maritime tracking, and citizen records. Autonomous firmware research yielded 12+ possible zero-days in one month.

Maritime domain awareness and civil registry match the target profile. Perimeter appliances run several patch cycles behind.

Government, defence, maritime, critical infrastructure

4

Scam economics restructured

4,700 AI personas across 20+ dating apps sent 2.36M messages to 25,000 users in two weeks. Three personas per human worker.

Fraud actor targeting Indonesian. Conversational plausibility is no longer a fraud signal.

Banking, payments, consumer platforms, law enforcement

Four changes worth making this quarter

The four changes below map one to one onto the findings above. Each names a single owner, because a control with two owners has none. Changes 1 and 2 remove initial access. They cover the two routes documented most often in this report: secrets shipped inside compiled code, and machine credentials governed at development tier while carrying production blast radius.

Changes 3 and 4 accept that some exposure cannot be removed and has to be detected instead. An adversary who rebuilds malware until it runs clean, or who exploits an appliance zero-day for which no signature exists, is caught on behaviour or not at all. The same logic applies to fraud. When more than 4k personas can sustain more than 2,3 million conversations, the message stops carrying a signal, and what remains is how the money and devices move.

#

Change

Mechanism

Owner

Timeline

1

Scan release artefacts, not repositories

Secret detection on every signed release build. Rotate first, audit second.

Head of AppSec with Software Engineer

30 days, then continuous in CI

2

Inventory and gate machine credentials

Named owner per AI key and per vendor token into your tenant. Log every call. Alert on volume, geography, time of day. Block model resellers at the egress rule. Document what each vendor compromise would reach.

CISO with Platform Engineering

Inventory 30 days, gateway 90 days

3

Detect on behaviour, and measure the tempo

Detections for token issuance anomalies, OAuth consent grants, device registrations, bulk exports, session-table reads. Publish mean time from alert to first analyst decision. Above 60 minutes, the stack does not engage.

SOC Manager with Detection Engineering

5 detections in 60 days, first tempo figure next cycle

4

Move fraud detection off conversational signals

Score transaction velocity, beneficiary account age, first-payment patterns, and device or session reuse across accounts. Retire controls that assume a human wrote the message.

Head of Fraud with Financial Crime

Signals instrumented in 90 days

Is your defensive stack ready for machine-speed execution? Learn how Zentara can help your team benchmark SOC tempo, secure machine credentials, and update your control posture.

Sources

Anthropic, Detecting and countering misuse of AI: September 2026, published 10 September 2026. https://www.anthropic.com/threat-intelligence-report-september-2026

POJK No. 11/POJK.03/2022; SEOJK No. 29/SEOJK.03/2022; BOC OJK Regulation No. 1 of 2026, effective 1 March 2026. 

Peraturan Bank Indonesia No. 2 Tahun 2024.

More like this, monthly.

What our teams are seeing in Indonesian threat activity and regulatory movement — written by the people running the SOC.

We use your address to send what you asked for and nothing else. No list is sold or shared. Privacy policy.

Have a security question this raised?

Our engineers answer directly — no qualification call first.