Anthropic just published its most detailed threat report yet: spies, fake newsrooms, mass surveillance and stolen API keys, all running on Claude. The striking part isn't the attacks. It's how cheap they've become - and who's missing from the list.
On 10 September 2026, Anthropic published its most detailed threat intelligence report so far. It covers eight months of work by the company’s Threat Intelligence team, from December 2025 through August 2026 and it is unusually blunt for something a company publishes about its own product.
The short version: state hackers, criminal crews, spyware vendors and propaganda outfits all tried to use Claude for their work. Anthropic caught them, banned them and then wrote down exactly how they did it.
The most useful finding isn’t about any single hacker. It’s this. None of the attacks were new. Phishing, stolen passwords, unpatched servers, SQL injection. Defenders have been dealing with all of it for twenty years. What changed is the price of running them.

What’s actually in the report
Anthropic split the findings into seven areas of harm: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and something they call illicit distillation.
Every operation described was disrupted. Accounts were banned, detections were built and in most cases Anthropic passed what it learned to law enforcement, affected companies and other AI labs.
One detail worth noting if you track model tiers: the misuse ran on Claude Haiku, Sonnet and Opus. Fable and Mythos-class models appear exactly once in the entire report, in a single distillation case.
Sophistication stopped being a clue
This is the finding threat analysts will be arguing about for months.
For decades you could make a decent guess about who was behind an attack by looking at how good it was. Sloppy, noisy, opportunistic? Probably a criminal. Quiet, custom-built, patient? Probably a government.
That shortcut is broken. In this report, a lone French-speaking hacktivist, a loose crew of financially motivated criminals and a Russian state espionage team all ran campaigns that looked structurally identical. Multiple victims at once. Custom tooling. Stolen data processed at volumes no human could handle by hand.
The thing separating them isn’t skill any more. It’s intent.
Anthropic puts the economics plainly. The expensive part of hacking used to be labour: reconnaissance, building tools, sorting through stolen data. All of that now runs inside an AI harness, in parallel, at machine speed. One breach in the report went from first access to bulk data theft in a matter of hours. Another went from a single stolen developer token to full admin control of a company’s cloud in about three.
The Russian operation that repaired its own malware
The case tracked as GTG-20006 is the one security teams should read twice.
Anthropic’s attribution lines up with public reporting on Midnight Blizzard, a Russian state-linked group. One operator used the handle “JackPoterz.” Targets included Ukrainian government ministries, European defence bodies, embassies and think tanks, more than twenty organisations in total.
Here’s the part that breaks the old model. The group pointed AI agents at their own malware and asked one question on a loop: has any security product spotted this yet? Whenever the answer was yes, the agents rewrote the malware, rebuilt it and tested again. They kept going until it came back clean. Only then did the tools get deployed.
Defenders used to slow attackers down by publishing a detection signature. That imposed real cost. Now the attacker’s fix loop closes faster than the defender’s detection loop opens.
The same group compromised hotel WiFi providers so that guests connecting to hotel networks were quietly redirected to attacker servers. They took over WhatsApp accounts by linking them as companion devices, with read receipts suppressed so victims never noticed their conversations being exported. Two former senior Ukrainian officials were targeted this way. In North Africa, they walked out with a national credential database holding more than 300,000 identity records.

Vibe hacking, industrialised
Another cluster, GTG-50014, involves operators suspected of ties to ShinyHunters, the collective known for large-scale data theft followed by pay-or-leak extortion.
One operator ran a credential harvesting pipeline across ten AWS servers. It downloaded 1.8 million Android apps, took them apart and scanned them for passwords and API keys that developers had accidentally baked in. Verified finds were piped straight into Telegram groups, sorted by type of secret.
Anthropic calls the working style “vibe hacking.” The operator gives the AI a goal, something like “get the data out of this environment,” and lets it work out the rest: read the system, write scripts, run them, summarise, repeat. Often the human doesn’t really understand the target environment. They don’t need to.
The damage was not theoretical. Over a terabyte stolen from one technology provider. Tens of millions of passenger records at an airline. At an energy company, the operators claimed they could remotely change the charging current on customers’ home EV chargers.
One operator was also collecting bug bounty payouts from companies they were extorting at the same time. Two payments, $2,000 and $5,000, from firms they had already broken into.
Your API key is the new loot
If you take one practical thing from this report, make it this one.
Stolen AI credentials have become a target in their own right, because they hand an attacker three things at once. Resale value, since there’s an established market for them. Free compute, because the attack workload runs on the victim’s bill. And cover, because the activity looks like it belongs to the legitimate account holder.
A hacktivist campaign in the report ran for a month entirely on stolen keys. ShinyHunters affiliates would breach a company, find its AI keys and immediately switch their own attacks over to run on them.
Then there’s GTG-50020, a Russian-speaking group that used to break into hotel booking platforms and decided to go after AI companies instead. They fed malicious instructions into an AI vendor’s automated testing sandbox and got it to hand over the production API keys it was holding. They then hit roughly thirty AI companies in four days with the same trick. Their stated goal was access to an unreleased Claude model. They never got it and Anthropic’s own systems were never compromised. Every key involved was stolen from a customer’s environment.
A separate group ran a fake reseller offering cheap Claude access. Customers’ traffic was quietly routed to a completely different model, while the reseller’s software stole their Anthropic credentials and sold them onward.
So: treat AI keys like production database passwords, because attackers already do. And if a deal on model access requires routing your traffic through a middleman you’ve never heard of, that is the scam.
Fake newsrooms, at scale
The influence operations section covers nine campaigns out of Russia, Iran, Turkey, Bangladesh, Kenya and the Gulf, aimed at audiences on six continents.
A France-based digital advertising agency ran roughly 70 fake news websites, each with its own invented journalists and a matching X account, backed by 250-plus fake commenting accounts using AI-generated profile photos. Output: at least 8,913 articles in about 20 languages. The network took whichever political side the client was paying for. Investigators caught it when several supposedly independent outlets published near-identical stories about the DRC-Rwanda conflict within three minutes of each other.

An Istanbul technology company sold a Malaysian election manipulation platform, described in its own marketing as a “military-grade, AI-driven, real-time political operations ecosystem.” It ran about a thousand fake X accounts with warm-up routines to make them look lived-in, profiled voters across all 222 parliamentary constituencies using real census data and fed a fake news site called Malaysia Pulse. One request logged in the system: a million artificial views on the sitting Prime Minister’s account.
In Russia, four individuals used Claude as a newsroom sub-editor. Their output ran on Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa and RT’s English newsroom. One of them, a former Sputnik Moldova editor-in-chief, pushed fabricated claims about Moldova’s president ahead of the 2025 parliamentary election. Another built on-air tickers and voiceover scripts for live Russian television and at least one confirmed piece made it to air.
The most personal case involved an operation aligned with the Iranian opposition group MEK. They cloned a real activist’s Telegram account, fed the model roughly 8,400 of his posts to learn his writing voice and then ran live political conversations with his contacts inside Iran. Those people had no idea who they were actually talking to.
Anthropic makes one honest point here. Most of this content reached almost nobody. Because they sit at the production stage, before anything is published, they often disrupt an operation before it has an audience at all. The exception is state media, where a real broadcast network handles distribution.
Surveillance, weapons and biology
The surveillance cases are the bleakest reading in the document. A single consultant working for Malian national security used Claude to build a mass interception platform covering every mobile operator in the country, roughly 25 million SIM cards, capable of generating dossiers on individuals. The warrant requirement on those dossiers was removed at the operator’s request.
A separate PRC-aligned operation ran covert recruitment against Uyghur targets in Syria. The operator didn’t speak Arabic. The model wrote the outreach in the right regional dialect and translated the replies as they came back.
On conventional weapons, Anthropic disrupted six cases. One involved a Yemen-based cell using Claude Code as the engineering team for a guided rocket’s navigation system. They test-fired it. It appears to have failed and within hours they were back asking why.
On biology, a researcher outside the United States used VPS infrastructure to get around a regional block and spent weeks planning avian influenza experiments involving mammalian adaptation. Classifiers kept those conversations on lower-tier models, which limited what he could get out of them. The pattern matters more than the outcome: researchers are actively working around regional blocks and falling back across multiple models to keep going.
The distillation section names names
This is where the report gets commercially awkward. Anthropic attributes illicit distillation campaigns, meaning harvesting a rival model’s outputs to train your own, to Alibaba, Moonshot, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax.
Alibaba’s campaign peaked at nearly three million exchanges a day from more than 3,500 fraudulent accounts, going after Claude’s reasoning on agentic and software engineering work. Anthropic counted over 151 million exchanges attributable to Alibaba between May and July 2026.
Moonshot and DeepSeek did something stranger. Instead of answering customer requests with their own models, they quietly forwarded those requests to Claude and showed Claude’s answers to their users. Over a ten-day window, Moonshot relayed close to 300,000 customer requests. Because that traffic passed through Anthropic, it also exposed whatever those customers had typed in, including live credentials from a Russian defence agency database.
Anthropic’s countermeasure is neat. Claude now summarises its internal reasoning before answering, which makes a stolen transcript much less useful as training data.
Where Claude pushed back
The refusals are worth reading, because they show the value and the limits of guardrails in the same breath.
In the Central African Republic operation, the model refused to name real people as militants in a way clearly designed to get security forces sent after them. The operator switched to anonymous-source framing instead. In the Malaysia case, Claude flagged a fabricated dossier as material for political defamation. The operator negotiated softer wording and carried on building.
Guardrails work. They also get talked around by anyone patient enough to try, which is exactly why the detect-and-ban side of the operation has to exist.
What the report doesn’t say
Read the list of countries and something stands out. Russia, Iran, China, Turkey, Bangladesh, Mali, Yemen, the Gulf. Europe is well represented too and not just as a victim: three of the named cases are French, including the ShinyHunters operator who registered a domain impersonating the French national police, the lone hacktivist who built the doxxing platform and the Paris-area advertising agency behind those 70 fake newsrooms. The Malaysia election platform traces back to a company in Istanbul.
What you will not find anywhere in 150-odd pages is a single case from the United States or Israel.
That is almost certainly not because nobody there is doing this. There are a few better explanations and they probably all apply at once.
The report isn’t a census. Anthropic says outright that these are the most notable and novel cases, not a representative sample. Picking for novelty naturally surfaces state espionage and propaganda machinery over, say, a domestic ransomware crew.
Then there’s the definition of misuse. This report covers violations of Anthropic’s policies. An allied government doing offensive cyber work is likely doing it under an enterprise agreement, on its own infrastructure, or with a different vendor entirely. That’s authorised use. It never enters this dataset in the first place.
Detection is uneven, too. Iranian operators had to use VPNs and foreign phone numbers because Claude is blocked in Iran and that evasion is itself a detectable signal. An operator working from Virginia trips no such wire.
And there’s the commercial reality. Anthropic sells to the US government and is currently in a public disagreement with the Department of Defense over contract clauses on mass surveillance and autonomous weapons. Naming Sputnik Moldova and naming a domestic agency are not remotely the same act. Ongoing law enforcement work limits what can be published as well.
From the outside you can’t tell which of those is doing the heavy lifting. That’s the point. This is a genuinely valuable document and it’s also a document about what one company can see, is permitted to say and chooses to put its name to. Read it as evidence, not as a map of the world.
What this means if you’re not a spy
Three things are worth carrying out of this.
Treat your AI keys as production credentials. Rotate them, scope them and go and check whether they’ve leaked into a mobile app bundle, a Docker image or a public repo. Attackers are scanning for precisely that, at industrial scale.
Assume you’re in scope. The old comfort of being too small or too obscure to bother with is gone. When reconnaissance costs almost nothing, everything connected to the internet is worth a look.
And if your security stack leans heavily on known-bad file hashes, expect that advantage to shrink. Adversaries are rebuilding their tools faster than signatures can be written.
Anthropic’s own closing point is the one to sit with. As models get more capable, the risks grow with them, unless the people building these systems and the people defending against them keep moving too.
Read the full report: Detecting and countering misuse of AI: September 2026