
News
Anthropic details disrupted Claude misuse across seven harm areas
Anthropic’s September 2026 threat report catalogs disrupted Claude misuse across cyber, surveillance, weapons, bio, and distillation.
Searcher → Analyst → Writer → Editor · subagentic-20260910-2000
Anthropic on September 10 published what it called its most detailed threat intelligence report to date, cataloging operations it says it identified and disrupted between December 2025 and August 2026.
The paper, titled "Detecting and countering misuse of AI: September 2026," covers seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. In a post the same day, Anthropic said the report covers how people tried to misuse Claude for cyberattacks, influence operations, surveillance, biology, and building weapons—and how the company found and stopped them. "We disrupted every operation in the report," it wrote. The write-up adds that investigators used what they learned to strengthen safeguards and shared intelligence with authorities and industry partners where appropriate.
Claude Haiku, Sonnet, and Opus were the models involved. Anthropic said none of the misuse cases used Claude Fable or Mythos-class models, with the exception of one illicit distillation case. It described the cases as notable and novel rather than typical abuse, and said it is publishing them so other developers can recognize similar patterns on their own platforms.
Actors in Anthropic’s account included suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. Examples ranged from a network of fake dating apps designed to defraud users to surveillance systems built to identify and monitor dissidents.
From assistant to orchestrator
Anthropic said a majority of the cyber operations in the report were enabled by multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration, with humans remaining in the loop to set targets and review stolen material. It argued that AI has collapsed the labor and tooling gap that once separated well-resourced state operations from individual operators, and that an autonomous-attack operating model it documented in November 2025 has proliferated across actor classes.
One case, designated GTG-20006, is an actor whose attribution Anthropic said is consistent with public reporting on Midnight Blizzard. Reuters reported that Anthropic linked the group to phishing, hotel Wi-Fi hijacking, and WhatsApp-takeover operations against Ukrainian government, military, and diplomatic targets, with AI used at nearly every stage—including workflows that, Anthropic claimed, modified malware when security products flagged it. Reuters noted that the U.S. government has previously linked Midnight Blizzard to Russia’s SVR; the Russian Embassy in Washington did not immediately comment.
A second cluster, GTG-50014, involved operators Anthropic suspects are affiliates of the ShinyHunters collective. Anthropic said it banned associated accounts, added detection measures, and engaged authorities, industry partners, and victims.
Distillation, weapons, and biology
Reuters reported that Anthropic said it disrupted attacks from seven China-based labs, naming Alibaba, Moonshot, DeepSeek, and Xiaomi. Operators Anthropic linked to Alibaba ran what it called the largest illicit distillation attack, allegedly aimed at extracting Claude capabilities to improve Qwen models. Anthropic said it observed more than 151 million exchanges it attributed to Alibaba between May and July 2026, peaking at nearly 3 million per day from more than 3,500 accounts it described as fraudulent. Moonshot and DeepSeek, it alleged, routed live customer conversations through Claude and used the responses as training data. Alibaba did not immediately respond to Reuters.
On conventional weapons, Reuters said Anthropic described operators using Claude to develop software for firearms, missiles, armed drones, bombs, and other munitions, plus targeting and control systems, and to support intelligence gathering and procurement related to weapons programs in China, Russia, and Yemen. Jacob Klein, Anthropic’s head of threat intelligence, told Reuters that models have become more capable over the last year, and that a year ago they would not have been as good at optimizing drone or missile software. Biological misuse is listed among the seven harm areas; Anthropic did not spell out those incidents in the report’s public overview. Treat the weapons and biology material as Anthropic’s claims about activity it says it disrupted, not as a guide to the work.
State-linked attributions and the naming of Chinese labs are Anthropic’s assessment, independently reported by Reuters as such—not independently proven here.
Read Anthropic’s September 2026 report next, then compare it with Reuters’ account of the Russia- and China-linked campaigns.