NewsMacroAnthropic Report Details AI Use in Cybercrime, Influence Campaigns and State Operations

Anthropic Report Details AI Use in Cybercrime, Influence Campaigns and State Operations

Author: Metaverse Post·

Key Takeaways

  • The report covers high-end misuse cases detected and disrupted across Russia, China, Iran and other regions, rather than measuring typical misuse frequency.
  • Threat actors used multi-agent systems to automate cyber operations, including phishing, malware development, credential harvesting and data exfiltration.
  • Anthropic identified influence campaigns, surveillance programs, weapons projects and dual-use biological research among the documented activities.
  • The company accused several Chinese laboratories of covertly extracting Claude outputs and reasoning traces to train competing models, with some relays allegedly exposing sensitive data.
  • Anthropic said none of the cases involved its most capable Fable or Mythos models except for one distillation-related incident.
Anthropic Report Details AI Use in Cybercrime, Influence Campaigns and State Operations

AI research company Anthropic has published its latest threat intelligence report, “Detecting and Countering Misuse of AI: September 2026”, detailing attempts by malicious actors to weaponize its Claude models for cyber operations, influence campaigns, surveillance, biological research, weapons development, fraud and model distillation.

The report covers activity detected and disrupted between December 2025 and August 2026. The cases involved suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors and propaganda institutions operating across Russia, China, Iran and other regions.

Anthropic said none of the documented misuse cases involved its most capable Fable or Mythos-class models, except for one case described in the distillation section. The company also emphasized that the disclosed incidents do not represent typical misuse. Instead, they were selected as the most sophisticated and novel threat activity identified to date. That means the report is a record of high-end documented misuse rather than a measure of how frequently these activities occur. Anthropic said it banned the associated accounts in every case, strengthened its safeguards based on investigative findings, and shared intelligence with authorities and industry partners.

We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report,… — Anthropic (@AnthropicAI) September 10, 2026

https://x.com/AnthropicAI/status/2098097512544444447?ref_src=twsrc%5Etfw

From Assistant to Orchestrator: Key Findings

The report’s central conclusion is that AI has shifted from an advisory tool to an operational orchestrator in cybercrime. In most of the operations examined, threat actors deployed multi-agent frameworks that autonomously performed reconnaissance, exploitation, credential harvesting and data exfiltration. Human participants primarily selected targets and reviewed the results.

One notable case, identified as GTG-20006, was linked to the Russian state-nexus group Midnight Blizzard. The group used AI-driven workflows for phishing, malware development and evasion, automatically rebuilding its toolkit whenever security products detected it. Separately, suspected ShinyHunters affiliates used AI to industrialize credential harvesting, decompiling 1.8 million Android applications in search of secrets and completing breaches in as little as two to three hours.

Outside cyber operations, Anthropic documented influence campaigns targeting elections and public opinion in Moldova, Kenya, Malaysia and Bangladesh. It also described state-aligned surveillance activity in China, Iran and Mali, including a platform designed to monitor roughly 25 million mobile subscribers.

The report further identified weapons development efforts, including a guided rocket program in Yemen and an autonomous drone swarm project in Russia. Its biological misuse section outlines five dual-use research cases, including gain-of-function work involving chikungunya virus and studies on adapting avian influenza. Anthropic said its classifiers largely contained these activities.

The report also details illicit distillation campaigns attributed to Chinese laboratories, including Alibaba, DeepSeek, Moonshot AI, Xiaomi and Zhipu. Anthropic accuses the laboratories of covertly routing user queries to Claude, harvesting reasoning traces and using the resulting outputs to train competing models. In several cases, the relay allegedly exposed sensitive corporate and government data to third parties without users’ knowledge.

Anthropic presented the disclosure as both a warning and a roadmap. The company said that as AI models become more capable, coordinated detection and defense efforts by the AI industry and governments will be essential to staying ahead of persistent adversaries.

Source: Metaverse Post