
Anthropic published its fourth threat intelligence report on September 10, describing how Claude was used in cyberattacks, monitoring, influence operations, weapon development, fraudulent activities and illicit AI model distillation. It includes identified activity between December 2025 and August 2026. It has suspected state-sponsored groups, financially motivated offenders, commercial spyware operators and propaganda institutions. Anthropic said it disrupted the operations, strengthened its safeguards and shared information with authorities and industry partners where appropriate. The company said the cases are not a comprehensive view of misuse, but a selection of the most notable activity it detected. However, none of these findings have been independently verified.
How Were Hackers and Governments Using Claude?
The report’s biggest findings is the escalating role of AI in the cybersecurity niche. Anthropic said attackers are moving beyond using Claude as an ordinary chatbot. They use AI to conduct several stages of an attack, including exploitation and data infiltration. In some cases, AI-centric workflows operated with limited human autonomy, although people remained accountable for crucial decisions such as reviewing stolen data.
Anthropic said it disrupted activity linked to affiliates of ShinyHunters, among the most prolific cybercrime groups currently active. In an operation, an actor mass-downloaded 1.8 million Android application packages, decompiled and scanned them for hardcoded secrets. The stolen credentials were later used as initial access for confirmed breaches.
I just went through Anthropic’s threat report & woah!
— zhod (@zhodonx) September 10, 2026
This is genuinely the craziest article I’ve read all month.
They documented hackers, governments, scammers and Chinese AI labs all using Claude in completely different ways.
& some of the cases are insane.
Here’s a TLDR;… https://t.co/dw4Qri9L4T pic.twitter.com/nurpofmfEy
The context also entails how Claude was used for monitoring and influence operations. Anthropic found nine influence campaigns originating from Turkey, Iran, Russia and regions across the Gulf, South Asia, Africa, and Europe. The operations focused on audiences across six continents and involved pseudo social media profiles. Alongside this, they also included false news sites and cooperated political messaging channels.
Surveillance was a major issue. Anthropic described operations in which Claude was used to observe dissidents, activists, ethnic groups, religious communities and offshore diaspora groups. In one case, Claude helped automate federal authorities’ briefings by processing 15 to 30 or more articles. Claude also scored and assessed the context for sensationalism and created standardized reports with minimal human oversight.
It also covers weapon development. Anthropic also disrupted a suspected Russia-linked cyber espionage campaign against Ukraine, and attempted to use Claude for biological weapons research. It did not identify the institutions, countries or agents involved in the biological cases. including a system created to identify target classes and issue detonation commands without a human in the loop. Anthropic said that the activity involved real hardware-in-the-loop testing. A China-based actor used Claude to develop an electronic warfare and air defense suppression software suite. It later changed its simulation scenario to targets in Taiwan.
Why is Anthropic Raising Concerns About AI Misuse?
The misuse does not constrain itself to conventional cybercrime. Anthropic found out about a China-based network of more than 20 dating applications. The applications used over 4,700 AI personas to communicate with at least 25,000 people during a two-week timeline. Real workers were brought into some discussions to make the false profiles look believable.
It also focuses on illicit distillation, where companies try to extract the abilities of a more advanced AI model. They then use it to train their own systems. Anthropic said it identified and disrupted distillation campaigns run by seven China-based labs: Alibaba, DeepSeek, Moonshot, Xiaomi, Zhipu, SenseTime and MiniMax. Anthropic called Alibaba’s the largest distillation attack it has measured, with more than 151 million exchanges between May and July 2026, peaking near 3 million a day across more than 3,500 accounts it described as fraudulent. It said the aim was improving Alibaba’s Qwen models.
Anthropic also reported more than 23 million exchanges attributed to Moonshot and more than 12.1 million exchanges attributed to DeepSeek. In both cases, Anthropic alleges the companies routed their own live customer conversations through Claude and trained on the responses. It said some exchanges contained sensitive information from individual users, multinational companies and state-affiliated actors, and that the practice is “likely inconsistent with privacy laws and the labs’ own terms of service.”
The organization said these incidents are molding its defenses. Anthropic has introduced protocols and rules to make reasoning transcripts less useful for unlawful distillations. It has also bolstered controls around malicious accounts and access patterns. Anthropic said the broader lesson is that as AI improves, attackers can operate faster and at greater scale with fewer resources. China’s Foreign Ministry said it was not aware of the report, adding that Beijing holds AI should be developed for good and opposes “distortion of facts and smears against the country.”









