Back to News
RSS feedwww.anthropic.com

Anthropic Reports Disrupted Misuse of Claude Across Cyber, Influence and Weapons Operations

Summary

Anthropic’s September 2026 threat-intelligence report describes operations disrupted between December 2025 and August 2026 in seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons, and illicit distillation. The cases involved Claude Haiku, Sonnet, and Opus; Anthropic says it found no misuse of Claude Fable or Mythos-class models except for one illicit-distillation case. Across the investigations, state-linked groups, financially motivated criminals, hacktivists, commercial surveillance vendors, propaganda institutions, and politically motivated individuals used Claude as a coding assistant, orchestration layer, analyst, content desk, or autonomous agent system. In cyber cases, multi-agent workflows performed reconnaissance, exploitation, phishing, malware modification, credential theft, data extraction, and persistence, sometimes operating across many victims with humans retaining target selection or reviewing results. Anthropic says AI reduced the labor and expertise needed for campaigns: one espionage operation automated phishing and malware redevelopment, a criminal cluster completed some breaches within hours, and another group used agent swarms for vulnerability research, exploit development, reconnaissance, and collection. The report also describes stolen AI API keys being resold or used as attack compute, fraudulent Claude resellers that harvested customer credentials, and attacks on AI wrappers and evaluation environments; one group attempted to obtain a pre-release Claude model but failed. Influence operations used Claude to create fake news sites, personas, political dossiers, propaganda, election-manipulation systems, and source-laundering pipelines across multiple regions. Surveillance cases involved profiling dissidents and diaspora communities, recruitment, transnational repression, social-media monitoring, and the construction of mass-interception or case-management systems. Weapons-related investigations covered guided rockets, drone swarms, anti-torpedo systems, electronic warfare, procurement, and intelligence on directed-energy weapons. Anthropic says it banned associated accounts, strengthened classifiers and behavioral detections, and shared indicators with authorities and industry partners, while acknowledging that safeguards were sometimes bypassed, especially when actors fragmented requests or re-prompted after refusals. The report distinguishes autonomy from harm: humans often retained consequential decisions, but agentic systems compressed attackers’ labor costs and increased operational speed, scale, and persistence.