Anthropic says malicious actors are moving beyond using generative artificial intelligence as aoperational layer capable of coordinating cyberattacks, processing stolen data, maintaining infrastructure and adapting malware with limited human involvement
The AI company’sSeptember 2026 Threat Intelligence Reportdescribes a broad collection of suspected state-backed, criminal and commercial operations that attempted to misuse its Claude models between December 2025 and August 2026.
The cases covered seven areas: cyber operations, surveillance, influence operations, conventional-weapons development, potentially dangerous biological research, scams and fraud, and the unauthorized extraction—or “distillation”—of model capabilities.
The activity involved Claude Haiku, Sonnet and Opus models. Anthropic said none of the reported misuse involved its newer Fable or Mythos-class systems, except for one illicit model-distillation campaign.
Anthropic said it identified and disrupted the operations, banned associated accounts, strengthened its detection systems and shared relevant intelligence with government authorities, technology companies and affected organizations. However, it cautioned that the incidents were selected because they were among the most serious or novel cases its investigators had encountered and should not be interpreted as representative of ordinary Claude usage.
The findings nevertheless offer one of the clearest indications yet that AI-enabled malicious activity is evolving from conversational assistance into automated, multi-stage execution.
“The risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources,” Anthropic said in itsSeptember threat intelligence report.
AI begins closing the operational loop
The most important development identified by Anthropic was the increasing autonomy of AI-supported cyber operations.
Earlier malicious use of large language models frequently involved relatively simple requests: writing a phishing email, translating a message, explaining a vulnerability or modifying a small piece of malicious code. In the campaigns investigated during 2026, Claude was reportedly incorporated into agentic frameworks that could execute tools, assess results and continue working towards an operator-defined objective.
Human attackers still selected targets and reviewed sensitive results, but AI systems increasingly performed the work between those decision points.
According to Anthropic, a majority of the cyber operations detailed in the report involved direct AI execution or orchestration. These workflows carried out reconnaissance, infrastructure preparation, exploitation, credential harvesting, lateral movement and data processing rather than merely advising a human operator.
That distinction is critical. An AI assistant may make an individual hacker more productive, but an AI orchestrator can allow one person to manage activity that would previously have required several specialists.
The report argues that this change is weakening the connection between an attack’s technical sophistication and the resources of the organization behind it. A small criminal group—or even a capable individual—can increasingly reproduce elements of an operation once associated with a state intelligence service.
That does not mean the model independently chose victims or initiated attacks. The cases remained human-directed. Instead, the concern is that attackers can delegate growing portions of the operational workload to software agents that work continuously, handle unfamiliar environments and retry failed tasks.
Russian-linked espionage campaign targeted governments and drone companies
One of the report’s most significant cases involved an actor Anthropic tracks as GTG-20006. The company said its attribution was consistent with public reporting about Midnight Blizzard, a Russian state-linked espionage group also known under names including APT29 and Cozy Bear.
Anthropic identified a Russian-speaking operator using the handle “JackPoterz,” whose activity and targeting were assessed as consistent with Russian state-nexus espionage.
The operation targeted more than 20 organizations, including Ukrainian and European government bodies, military and intelligence organizations, embassies, diplomatic missions, think tanks, defence companies and people connected to US foreign policy.
Ukraine and military drone technology appeared to be recurring priorities. The operator scanned email and remote-access systems belonging to more than two dozen Ukrainian government organizations and reportedly compromised companies involved in drone components and vision systems.
Anthropic said the actor bulk-exported mailboxes from at least two drone-component manufacturers and stole a complete software development kit associated with a drone vision platform. The stolen material was then analyzed to reconstruct product architecture, hardware components, supplier relationships and information about an unannounced product.
The campaign also demonstrated how AI can connect activities across the intrusion lifecycle.
Claude-assisted workflows were allegedly used to research targets, identify exposed services, register deceptive domains, configure phishing infrastructure, deliver messages and monitor command-and-control systems for successful compromises.
The actor maintained several Windows implants, an Android surveillance tool, an iOS exploitation chain, a credential stealer and a phishing platform built to imitate government services. Malware names identified by Anthropic included PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc, GiftDrop and DarkSword.
More significantly, AI agents were used to monitor whether security tools had detected the operator’s malware. When a security product began identifying an implant, the automated workflow could modify and rebuild the malware, test the revised version and continue iterating until it was no longer detected.
This process potentially reduces one of defenders’ traditional advantages. Publishing a signature or indicator may no longer impose a lengthy redevelopment cost on the attacker if an AI-controlled system can rapidly adjust code and redeploy it.
Anthropic warned that capable attackers could increasingly “close the loop” between detection and evasion, placing the cost of repeated adaptation back onto security teams.
Hotels used as an indirect route to priority targets
The same suspected Russian-linked operation allegedly compromised at least three providers of hotel guest Wi-Fi services.
The attackers used administrative credentials to alter DNS settings and redirect connected devices towards infrastructure under their control. Information associated with hotel guests—including device identifiers and IP addresses—was sent to attacker-operated systems.
Victims could then be shown ClickFix-style social-engineering prompts designed to convince them to execute commands or install supposed updates. The operation prepared payloads for Windows, Android and iOS devices.
The attackers reportedly combined information from hotel-management systems with data collected from individual devices to identify higher-value targets, particularly Ukrainian officials and people connected to drone manufacturers.
Microsoft previously documented a related compromise and malware-delivery technique under the name CaptiveCrunch
The operation also targeted WhatsApp accounts by silently linking attacker-controlled browsers as companion devices. Automation based partly on the open-ons were exported. Anthropic said at least two former senior Ukrainian officials were targeted
Elsewhere, the actor exploited authorization weaknesses in camera-streaming services to harvest access tokens and view live feeds.
During a separate intrusion into a North African government technology authority, stolen VPN credentials allegedly enabled the attacker to compromise a central account server. Anthropic said the resulting theft included more than 300,000 national identity records and commercial registry information covering over 500,000 companies.
The actor also built a Microsoft 365 espionage platform using device-code phishing. That operation resulted in access to mail from at least eight organizations, including a prosecutor’s office, a military education institution and a regional intergovernmental body.
ShinyHunters affiliates scale “smash-and-grab” intrusions
Anthropic also described several financially motivated clusters it suspects were operated by affiliates of the ShinyHunters cybercriminal collective.
Unlike the more selective Russian espionage operation, these actors allegedly conducted broad credential harvesting, opportunistic compromise, supply-chain theft and data-extortion campaigns.
One French-speaking operator using the aliases MeowSHA, frkoo and blazespider reportedly operated 10 Amazon Web Services EC2 workers that downloaded approximately 1.8 million Android application packages from multiple sources.
The applications were decompiled and scanned with TruffleHog for hardcoded credentials, API keys and other secrets. Verified results were automatically forwarded to Telegram groups divided into more than 100 categories. A parallel operation harvested GitHub email addresses and personal access tokens.
These stolen credentials reportedly supplied initial access for many of the operator’s confirmed breaches.
In one technology-sector compromise, attackers stole more than one terabyte of data, including hundreds of thousands of national identification records and millions of payment-card records. The material was placed on a public website to pressure the victim into paying an extortion demand.
Another compromise gave attackers access to systems containing tens of millions of airline passenger records. At an energy-sector organization, the operators claimed they could remotely change the charging current of electric-vehicle chargers installed in customers’ homes.
Supply-chain access substantially increased the potential number of affected organizations. Following the compromise of one software-as-a-service provider, an affiliate allegedly extracted information belonging to approximately 200 downstream customers.
The actor subsequently dumped more than 2,100 Microsoft Entra ID token sets associated with over 40 corporate tenants in roughly 34 hours.
Anthropic said AI agents performed nearly all the work in some of these intrusions. The models examined APIs, interpreted unfamiliar authentication systems, created privileged tokens, generated scripts and repeatedly extracted information across different customer environments.
One enterprise software breach took only hours to progress from initial access to mass data theft. In another incident, a single stolen developer token was converted into full administrative control of a cloud environment in approximately three hours.
The company characterized this operating style as “vibe hacking”: a person provides a broad objective—such as using a credential or finding valuable data—while the AI explores the environment, writes and executes tools, assesses the results and continues until the objective is met.
Crucially, Anthropic said the attackers stole Claude API keys from customer environments and used them to support secondary attacks. Anthropic’s own infrastructure was not breached in those incidents.
AI turns exposed secrets into an industrialized attack pipeline
The ShinyHunters-linked cases highlight a security problem that extends far beyond prompt filtering.
Attackers searched mobile applications, container images, code repositories, client-side scripts, cloud-storage systems, credential stores and deployed AI agents for reusable secrets. The material was then automatically validated, categorized and ranked.
A working credential could be used to dump cluster-wide secrets, manufacture administrative tokens, compromise continuous integration and deployment systems, extract database contents or access downstream tenants through vendor integrations.
Stolen information was moved through consumer storage, attacker-controlled network-attached storage, Telegram bots, compromised cloud accounts and command-and-control infrastructure. Credentials and stolen databases were then retained for reuse, resale, financial theft or extortion.
This creates a reinforcing cycle: attackers steal cloud or AI credentials, use those credentials to acquire additional computing capacity, and deploy that capacity to search for more targets and secrets.
For organizations, the implication is that an exposed API key should no longer be treated solely as a billing risk. It may become infrastructure for attacks on the organization itself, its suppliers or unrelated third parties.
Chinese-speaking operators build an automated “exploit foundry”
Another investigation focused on GTG-10007, a Chinese-speaking group believed to be operating from Changsha in Hunan province.
Anthropic said two suspected operators were undergraduate students studying computer and communications engineering. One had previously interned at security company Sangfor and was interviewing for an offensive-security position at QiAnXin.
The group reportedly used Claude as both an engineering tool and an orchestration layer for reconnaissance against government networks in Europe, Southeast Asia and the Middle East, malware development, production-system intrusion attempts and continuous vulnerability research.
The company described the operation as an “exploit foundry”—an automated environment where AI agents can investigate software, test vulnerabilities and develop exploitation methods around the clock.
Historically, attackers have been constrained by the limited supply of skilled exploit developers and reliable vulnerability research. Automated AI workflows could increase both throughput and persistence by allowing agents to continue examining targets even when human operators are unavailable.
This does not mean that every AI-generated exploit will work. Vulnerability research still requires validation, technical judgment and suitable test environments. But the report suggests AI is reducing the time and expertise required to understand complex software and convert a potential weakness into a usable capability.
Independent coverage of the report similarly highlighted its finding that smaller groups are increasingly able to reproduce state-level operational patterns, including coordinated intrusion and exploit-development workflows.Cases included the Russian-aligned campaign, ShinyHunters-affiliated breaches and the Chinese exploit-development operation.
Mass surveillance built with AI as the engineering workforce
Anthropic’s findings extend beyond conventional hacking.
The company said state-aligned actors, government contractors and surveillance vendors used Claude to help build systems capable of monitoring communications, correlating identities and producing dossiers on political targets.
In one of the most extensive cases, a suspected independent consultant in Bamako allegedly used Claude as the principal engineering resource for Lakana 360, a domestic interception platform intended for Mali’s national intelligence service.
Anthropic said the system was designed to monitor approximately 25 million SIM cards across all three national mobile operators. Its proposed capabilities included the collection of call records, text messages and voice communications, followed by the generation of intelligence dossiers for selected telephone numbers.
Investigators found that a legal-control component requiring court authorization had been removed at the operator’s request. The dossier system was configured without a default warrant requirement and with indefinite data retention, according to the report.
Elsewhere, an entity identified as S2T Unlocking Cyberspace used Claude to build a commercial platform for profiling social-media users in Iran and the Persian Gulf. It mapped users’ locations, divided individuals into demographic categories and produced Arabic-language intelligence reports.
Anthropic said its findings corroborated elements of earlier reporting by Forbidden Stories concerning an S2T surveillance product discovered in documents leaked from the Colombian military.
Chinese public-security-linked operators also used Claude to monitor petitioners, rights defenders, Hong Kong democracy campaigners, organizers of Tiananmen Square commemorations, Uyghur groups and overseas human-rights organizations.
One municipal cyber police unit reportedly used Claude Code and custom automation to query a government surveillance database, extract information from websites and generate daily reports. Another operation produced pre-operational information about venues where lawful overseas protests were expected to occur.
Iranian state-linked users allegedly developed tools including a messenger de-anonymization system, a phone-number identity resolver, a national-ID phishing page, a Telegram mass-reporting bot and a malicious Firefox extension disguised as a prayer-times utility.
Anthropic said it banned accounts associated with the activity and added the observed behavioral patterns to its detection systems.
Propaganda operations gain an automated production desk
AI was also integrated into organized influence campaigns.
Anthropic said it removed four accounts used to produce polished material for Russian state-owned or state-funded media. The generated content was allegedly distributed through outlets including Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa and RT’s English-language operation.
Rather than merely drafting isolated posts, the actors used Claude as an editorial and content-production system capable of generating material at a volume that would otherwise have required a larger team.
Other campaigns reportedly used fabricated news organizations, coordinated social-media personas and automated publishing systems to influence audiences in Africa, Asia and Europe.
The Associated Press reported that Anthropic identified nine influence-operation cases linked to actors in Russia, Iran, Turkey, the Persian Gulf, South Asia, Africa and Europe. Some operations established hundreds of accounts that appeared to represent ordinary users before coordinating their messaging around the same political narrative. AP News
AI providers may have an unusual opportunity to identify these campaigns before the content reaches social networks. A platform such as Facebook or X generally sees an influence operation after its accounts and posts have been deployed; a model provider may observe the planning, persona creation, translation and production phase.
However, this visibility also places substantial investigative and policy authority in the hands of private AI companies.
Claude used in conventional-weapons programs
Anthropic said it disrupted six operations connected to conventional-weapons research or procurement: three based in China, two in Russia and one in Yemen.
The activities included work involving missiles, armed drones, autonomous targeting, munitions and weapons-related procurement. Reuters summarized the report as documenting attempts to use Claude for biological-weapons-related research, Russian-linked cyber espionage and Chinese misuse of the model.
One Russian-linked actor allegedly worked on autonomous drone-swarm software that included target selection and lethal engagement functions. A China-based operation used Claude to help prepare technical material relating to an anti-torpedo fire-control system and examine US naval systems. A Yemen-based actor worked on missile-guidance technology, although a reported field test was unsuccessful.
An Iran-linked group used Claude for open- naval vessels, including the analysis of ship-tracking information, photographs and satellite imagery
Another actor used Claude to automate procurement workflows involving technologies with possible Russian defence or aerospace applications. The system combined supplier information, processed spreadsheets and generated commercial correspondence.
Individual procurement requests can appear routine when examined in isolation. A request for quotations, shipping information or supplier lists may be indistinguishable from legitimate business activity. The risk only becomes apparent when those interactions are connected across time and evaluated alongside details about end users, payment routes and attempted export diversion.
Potential biological misuse exposes limits of prompt-based safeguards
The report’s most sensitive findings involved five cases in which users sought assistance with research that Anthropic believed could support biological-weapons development.
One operation involved a reseller platform that allegedly bypassed regional access restrictions to serve virologists working on a state-sponsored grant related to gain-of-function research on the chikungunya virus.
Chikungunya is a mosquito-borne disease that can cause fever and severe joint pain. The proposed work concerned viral transmissibility and immune evasion—properties that could be relevant to developing vaccines and treatments but could also make a pathogen more dangerous.
Anthropic said Claude blocked a request to help write a grant application connected to the work. The operators then attempted to route rejected prompts to systems with less restrictive protections.
Another researcher in an unsupported region reportedly spent weeks using Claude to plan experiments involving mammalian adaptation of avian influenza. Anthropic did not name the individuals, institutions or countries involved and explicitly said it was not asserting that the scientists intended to cause harm.
That caveat is essential. Much advanced biological research is inherently dual use: knowledge that could support a vaccine or therapeutic intervention may also help increase a pathogen’s transmissibility, resilience or ability to evade immunity.
Prompt-level classifiers have difficulty resolving that ambiguity, particularly when requests are individually legitimate and harmful intent is concealed across many interactions.
Anthropic acknowledged that older systems such as Claude Opus 4 and Sonnet 4.5 were previously assessed as being below the threshold at which they could materially assist a sophisticated researcher with dangerous biological work. With newer models, the company said the evidence is no longer sufficiently certain to make the same assurance.
It consequently introduced stronger restrictions for advanced dual-use biology requests in models including Claude Fable 5.
AP reported that Anthropic’s disclosures came amid broader calls for governments to regulate advanced AI rather than leave technology companies to make society-wide judgments about acceptable use without public oversight. AP News
A warning about evidence and attribution
Although the report provides detailed case studies, infrastructure indicators and examples of attacker workflows, its conclusions should be read with appropriate caution.
Most of the underlying telemetry is controlled by Anthropic and cannot be independently reviewed in full. Some actor identities and country-level links are assessments rather than publicly proven findings. The company uses internal “Generative Threat Group” designations that do not always map cleanly to threat groups tracked by other vendors.
The report also focuses on the most serious activity discovered by Anthropic, not the average use of its services. It therefore establishes that advanced misuse is occurring but does not independently demonstrate how prevalent it is across the wider AI ecosystem.
At the same time, the operational details align with a broader direction already visible in cybersecurity: attackers are increasingly incorporating language models into reconnaissance, scripting, social engineering and information processing.
What is changing is the level of integration. AI is no longer confined to writing phishing messages or explaining code. In the cases Anthropic documented, it was embedded into repeatable workflows that could operate tools, interpret unfamiliar systems, process large volumes of stolen information and revise offensive software when defenses responded.
What security leaders should take from the report
The immediate threat is not a fully independent machine selecting victims and launching attacks without human direction. It is a human-controlled system that allows fewer operators to conduct more sophisticated activity, against more organizations, at higher speed.
That changes the assumptions on which many security programs are built.
Static malware signatures will remain useful, but organizations will need behavioral detections capable of identifying repeated adaptation. Credential rotation must include cloud tokens, OAuth grants, development secrets, session cookies and AI API keys—not only employee passwords.
Security teams should monitor AI credentials for unusual geography, abrupt usage increases, unfamiliar tool-calling patterns and access from compromised workloads. Organizations should also scan applications, repositories, containers and CI/CD systems for embedded secrets before criminals industrialize the same process.
Defenders should treat service providers as part of the attack surface. The ShinyHunters cases show how one compromised SaaS company can expose hundreds or thousands of customers, while the hotel Wi-Fi operation demonstrates how attackers may compromise an intermediary simply to reach selected individuals.
Most importantly, organizations should prepare for attackers whose tools can change more quickly than traditional detection engineering cycles.
Anthropic’s report does not show that human hackers have become obsolete. It shows that a human operator can increasingly assign objectives to an AI system and allow it to perform much of the technical work needed to achieve them.
The emerging contest is therefore not simply AI attacker against human defender. It is an automation race in which both sides are attempting to compress the time between observing a change, deciding how to respond and executing that response.
For governments, enterprises and AI developers, the central question is no longer whether powerful models can be misused. Anthropic’s findings indicate that they already are. The more difficult question is whether collective defenses can mature quickly enough to prevent AI-enabled operations from becoming cheaper, faster and dramatically easier to scale.