Anthropic has published a self-reported threat intelligence report detailing eight months of disrupted attempts to misuse its Claude models, spanning cyber operations, disinformation, state surveillance, weapons development, biological research, romance-scam fraud and a wave of unauthorised model distillation by Chinese AI labs.
Published on 10 September and covering activity from December 2025 to August 2026, the report is Anthropic's own account of investigations it says it carried out, actions it took, and intelligence it shared with authorities and industry partners. The company says Claude Haiku, Sonnet and Opus models featured in nearly all disrupted cases, with only one instance touching its more restricted Fable or Mythos-class models. Anthropic argues sophistication is no longer a reliable signal of who is behind an attack, since AI has "collapsed the labor and tooling gap" that once separated well-resourced state operations from lone individuals.

Cyber operations
Anthropic's largest section covers cyber activity. It details a suspected Russian state-linked espionage campaign, tracked internally as GTG-20006 and which the company says is consistent with public reporting linking the actor to the group Midnight Blizzard. According to the report, one operator used the handle "JackPoterz" and the actor used AI-driven workflows to automatically rebuild and redeploy malware whenever it was flagged by security products, and targeted more than 20 organisations including Ukrainian government ministries, defence bodies and military drone manufacturers, in one case reverse-engineering a complete drone vision system's software development kit over several days, recovering its architecture, hardware bill of materials and details of an unannounced product. The same actor is said to have compromised hotel WiFi providers to deliver malware to guests' devices and hijacked WhatsApp accounts belonging to at least two former senior Ukrainian officials, while separately breaching a North African government technology authority and exfiltrating more than 300,000 national identity records and commercial registry data on over half a million companies.
Separately, Anthropic describes a Chinese-speaking group it says it traced to university students in Changsha, Hunan — one with a prior internship at security firm Sangfor and reportedly interviewing for a role at another, QiAnXin — running what it calls an autonomous "exploit foundry" against roughly fifty organisations globally. The group's workflow, Anthropic says, involved AI agents surveying decompiled firmware images, forming vulnerability hypotheses against a self-curated knowledge base, then writing and iterating exploit code until it succeeded, with one workflow against network appliances yielding more than a dozen possible zero-day findings in a single month.
Another case, linked to the financially motivated ShinyHunters collective, describes a French-speaking operator running a credential-harvesting pipeline across ten AWS EC2 workers that mass-downloaded 1.8 million Android APKs in search of hardcoded secrets, alongside a separate actor who escalated from a single stolen developer token to full administrative control of a victim's cloud environment in roughly three hours. The report notes AI agents performed "nearly all" of a related 34-hour data-extraction operation spanning more than 40 corporate tenants, and describes one operator running a storefront selling stolen payment-card data that impersonated the French national police.
Anthropic also details GTG-50029, a single French-speaking hacktivist who it says compromised at least four websites using a previously undocumented WordPress vulnerability. Separately, the same actor exfiltrated roughly 140,000 records containing users' political opinions from a campaign management platform, and built a bespoke doxxing platform loaded with tens of millions of rows of breach data, including national health identifiers, which the report calls "one of the clearest cases we have seen of AI-assisted software engineering applied directly to a mass attack on privacy."

Influence operations
The report details nine influence campaigns it says originated in Russia, Iran, Turkey and elsewhere, targeting audiences on six continents. One case, tracked as GTG-24015, describes four accounts used as an editorial and news production desk feeding content into Russian state-media outlets including Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa and RT's English-language newsroom. Anthropic says one actor, a former Sputnik Moldova editor-in-chief, used Claude to turn Moldovan news and opposition social media posts into Russian-language articles amplifying fabricated, defamatory claims about Moldova's president Maia Sandu ahead of the country's September 2025 parliamentary election, while a separate operator produced broadcast-ready tickers, captions and voiceover scripts for RT drawing on Russian newswires and material attributed to Russia's foreign intelligence service.
Iran features prominently too. The report describes three state-aligned accounts linked to the Islamic Culture and Communications Organization (ICCO), the Islamic Propaganda Office of Khorasan Razavi, and the Islamic Propaganda Organization's Bina Cultural Observatory, all tied to what the actors themselves called a "soft war" or "cognitive warfare" programme. Anthropic says the ICCO account produced a complete organisational plan for the funeral of Iran's Supreme Leader, while the Khorasan Razavi unit ran a multi-province "content factory," internally codenamed Manjanegh (Catapult), using dozens of activists to repackage state security reporting under invented personas. The Bina-linked account is said to have generated messaging in the voice of an IRGC spokesperson and attributed fabricated claims to Western think tanks including CSIS, Brookings and RAND during the 2026 US-Israel-Iran war.
Anthropic also says it disrupted a French-run commercial "influence-as-a-service" operation, tracing it to LKM Company, a France-based digital advertising agency, which published more than 8,900 fabricated articles across roughly 70 fake news sites in around 20 languages for clients spanning the political spectrum, and a campaign in Malaysia that used real electoral data to micro-target voters along racial and religious lines using a purported "military-grade, AI-driven" political operations platform, traced to an Istanbul-based technology company. A separate case describes a distributed operation linked to the Iranian opposition group MEK/NCRI, in which an actor cloned a real activist's Telegram account by feeding roughly 8,400 of his posts into a shared AI agent, then ran live political conversations with his contacts inside Iran who were, Anthropic says, unaware they were speaking with an AI-assisted account.

Surveillance operations
On surveillance, Anthropic describes a single Bamako-based consultant it says used Claude as the primary engineering workforce to help build a domestic surveillance platform, "Lakana 360," for Mali's state intelligence service capable of monitoring roughly 25 million SIM cards across the country's three mobile networks, with a warrant requirement for generating individual intelligence dossiers reportedly removed at the operator's request and replaced with indefinite retention. Other cases in this section describe Chinese state-security-linked actors compiling dossiers on Catholic cardinals, the Presbyterian Church in Taiwan, Tibetan Buddhist and Falun Gong communities, and a municipal cyber police unit that used Claude Code to run a domestic sentiment-monitoring pipeline while a police academy student separately obtained suppression guidance naming ten private citizens for "control" after Claude's initial refusal was overcome on re-prompting. An Israeli-Singaporean commercial vendor, S2T Unlocking Cyberspace, is separately said to have used Claude to profile and geolocate social media users across Iran and the Gulf into six demographic categories, corroborating details from a 2023 Forbidden Stories investigation into a leaked company brochure.

Conventional weapons
In what Anthropic describes as its first disclosure covering conventional weapons misuse, the report details six cases. One describes a Yemen-based cell running three parallel weapons programmes — a guided rocket, a multi-stage ballistic missile with a stated range goal above 2,000km, and a multi-variant missile including a hypersonic glide vehicle — using Claude Code to develop guidance software for a rocket that was subsequently test-fired in the field, with the actors reportedly returning to the model within hours of the test to diagnose its failure. Anthropic says the cell managed several Claude instances simultaneously, assigning each a distinct role akin to a small engineering team, and had separately built an offline simulation toolkit that no longer depends on Claude.
Another describes a Russia-based group, operating under the name "DronDoc" or "Serafim" and reportedly linked to a regional university with ties to the Russian Academy of Sciences, building an autonomous first-person-view drone swarm complete with shared swarm memory, fault-tolerant coordination logic and a control-link geolocation module to find enemy drone operators. The group trained a computer vision classifier on scraped Ukrainian combat footage to distinguish "enemy" from "friendly" targets, with the onboard system able to select human targets and issue detonation commands without a person in the loop, and repeatedly used a fixed coordinate in Donetsk Oblast as its demonstration strike point.
Two further cases involve Chinese-linked actors. One drafted a Chinese-language specification and a 200-page technical proposal for an anti-torpedo fire control system intended for approval by a Chinese defence manufacturer, repeatedly prompting Claude to role-play a hostile reviewer to sharpen successive drafts. The other built targeting software for electronic warfare and air-defence suppression across roughly 16 modules and 12 iterated versions, which Anthropic says was mid-project redirected toward a simulated scenario involving 12 targets in Taiwan, including a command bunker, early-warning radar site and Patriot and Tien Kung missile batteries. Part II of this section covers two further cases of weapons-adjacent procurement and intelligence gathering: a Moscow-based actor sourcing German-made magnetometers and space-grade solar wafers through Chinese intermediaries for Russian government and defence customers while explicitly briefing a director on evading European trade controls, and a China-based defence intelligence writer compiling a 23-page briefing on a foreign military's high-power microwave weapons for restricted circulation to senior Chinese Communist Party and military leadership.

Biological misuse
Anthropic says it identified five cases of dual-use biological research it judged concerning enough to disclose, while stressing it does not allege the researchers involved intended harm. One describes a reseller platform serving virologists it says were pursuing chikungunya gain-of-function research affiliated with a military research institute, which routed refused requests to more permissive competitor models when Claude declined them, and which re-established access within days of being banned using fresh identities. Others describe a researcher outside the US spending weeks exchanging thousands of messages with Claude while planning mammalian-adaptation experiments on avian influenza — work Anthropic says was confined to its weakest models, Claude Sonnet 4 and Haiku 4.5, limiting the uplift provided largely to clerical and study-design assistance — and a reseller relay serving more than a dozen customers that had Opus 5 draft a complete orthopoxvirus immune-evasion grant application, covering hypothesis, experimental design, dosing and statistics, in about an hour.
The final two cases involve state-supported researchers: one developing a venom toxin peptide atlas and generative optimisation pipeline covering both analgesic and export-controlled paralytic targets, and another computationally redesigning a bacterial toxin subunit and a WHO priority-list haemorrhagic fever virus protein while deliberately instructing Claude to keep descriptions of the agents "deliberately low fidelity" in quarterly progress reports. Anthropic says its safety classifiers successfully confined the most sensitive of these interactions to its weakest, least capable models, but acknowledges dual-use biological research is inherently difficult for classifiers alone to police.

Scams and fraud
The report also details a Chinese app studio, tracked as GTG-15001, which Anthropic says used Claude to build a network of more than 20 dating apps and power thousands of AI personas that conversed with users while the apps were marketed as fully human. Over a two-week window in April, Anthropic says it identified more than 4,700 distinct AI personas engaging with at least 25,000 individuals, in a roughly three-to-one ratio of AI personas to real gig workers recruited to handle video calls and social media verification that the AI could not perform, with a weaker non-Anthropic model separately generating quick-reply suggestions for those workers and an image-editing model producing avatar photos. The report says the apps were engineered with a UI controller that activated only during App Store and Play Store review, with class names differentiated across more than 20 app variants specifically to defeat platform similarity checks, and that in a small number of cases the model's own reasoning flagged apparent user distress or disclosures of serious illness without the system refusing to continue the in-persona conversation.

Illicit distillation
Anthropic's final section covers what it calls illicit distillation: unauthorised, industrial-scale efforts to extract a model's capabilities and replicate them in another model, typically enabled by fraud involving fake accounts, stolen credentials and proxy services. The company says it disrupted campaigns from seven China-based labs since its first disclosure of this activity in February. It describes Alibaba's Qwen team as running "the largest distillation attack we have ever measured," peaking at nearly 3 million exchanges per day across more than 3,500 fraudulent accounts and totalling more than 151 million exchanges between May and July, by injecting a fixed prompt that forced Claude to expose its reasoning inside inline text tags before training its Qwen 3.5, 3.6 and 3.7 models on the harvested transcripts. Anthropic says Alibaba also used Claude to help build its own reinforcement-learning training infrastructure and advance model architecture research, and that when one pool of roughly 5,000 fraudulent accounts was banned, traffic quickly shifted to a second pool later found to be shared with DeepSeek and Xiaomi.
Separately, Anthropic says Moonshot AI and DeepSeek were each found to have silently routed customer requests to Claude and served its responses to users who believed they were using the companies' own Kimi and DeepSeek models respectively. Both are said to have used a "cross-session replay" technique, saving Claude's reasoning-signature reference, starting a new session, then prompting Claude to convert that signature back into its full reasoning trace to circumvent Anthropic's anti-distillation controls. Moonshot's relayed traffic reportedly included a user Anthropic assessed as likely affiliated with the Chinese military analysing CCTV surveillance footage of a tracked individual, while DeepSeek's relayed traffic is said to have exposed live credentials for a Russian government database associated with its Ministry of Defence and internal tooling built for a municipal Public Security Bureau's case-management system in China.
Anthropic also describes Zhipu (branded outside China as Z.ai) running a chain-of-thought extraction pipeline against Claude Opus 4.8 using 273 fraudulent accounts, and separately attempting to target the cyber capabilities of Anthropic's Fable model ahead of the release of its GLM 5.3 model before abandoning the attempt after Fable's cyber safeguards degraded the attacks, switching instead to Opus 4.6 and a rival US lab's model. A further case describes Xiaomi replaying its own users' coding sessions through Claude, which Anthropic says coincided with the end of a free trial period for its MiMo-V2-Pro model, exposing names, contact details and corporate data belonging to hundreds of Xiaomi users. Rounding out the section, Anthropic describes SenseTime purchasing harvested Claude transcripts from third-party data vendors to build its own distillation pipeline, and says MiniMax operated an undisclosed shell-company proxy service offering access only to Anthropic's and OpenAI's models — and none of MiniMax's own — which Anthropic says suggests the service exists specifically to harvest exchanges with rival US models for training.
