In September 2026, Anthropic published a new Threat Intelligence Report covering Claude misuse it says it identified and disrupted between December 2025 and August 2026. The report spans seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit distillation. The models involved were mainly Claude Haiku, Sonnet and Opus; Anthropic says it found no Fable or Mythos involvement except in one distillation case. This is Anthropic’s disclosure of its own threat-intelligence observations, not independent confirmation of every attribution.

What cases does the report describe?

The report lists operations of very different sizes. Anthropic says a China-linked actor used Claude to build a roughly 16-module electronic-warfare software suite covering radar and communications detection, jamming effectiveness, target ranking and mission assignment. It also describes an operation it assesses as Russian-linked that used AI workflows for phishing, tool development, persistence and data exfiltration, alongside Iran-linked profiling and surveillance tooling and a fraud service populated with AI personas.

One notable measurement is Anthropic’s claim that a dating-fraud operation generated about 2.36 million messages over two weeks, with roughly three AI personas for every human participant. Humans handled tasks AI could not easily perform, such as live video calls and social-media follows. Another case involved a guided-rocket program in Yemen; Anthropic says it observed a live field test but no operational weapon resulted. Together, the cases show that risk is not only in generated text, but in the speed and scale created when outputs are connected to real workflows.

AI is moving from chatbot to orchestration layer

Anthropic’s cyber cases go beyond using Claude as a search tool. Multi-agent frameworks divided reconnaissance, vulnerability research, tool building, deployment, data organization and exfiltration checks, while humans set targets, adjusted workflows or reviewed outcomes. Anthropic says one actor even used AI to monitor whether malware was detected and automatically modify, rebuild and redeploy it after detection.

Defenders therefore cannot use only the text of a chat as their signal. They also need to watch tool calls, connections, file actions, agent handoffs and abnormal speed. Anthropic says it banned the accounts, strengthened its classifiers and shared indicators with government and industry partners where appropriate. Platform safety is moving from reviewing individual answers toward monitoring long workflows and exchanging intelligence across organizations.

What should not be treated as independently proven?

The report’s attributions and details need to be read at the right evidence level. It uses Anthropic’s internal GTG labels and investigative data, and some descriptions are assessments of suspected state backing or tradecraft consistent with a country nexus. Readers cannot reproduce every evidentiary chain from the public report alone. This article therefore attributes claims to Anthropic rather than presenting every allegation as a court-established fact.

Nor should AI involvement be read as proof that AI completed an entire attack autonomously. The report repeatedly describes humans setting targets, supplying access or reviewing exfiltration, and it also records refusals and account bans. Anthropic says attackers fragmented requests, tested safeguards and tried to bypass controls. The engineering question is how people, models, tools and permissions combine, not whether a model acted alone.

What does this change for defenders and users?

The practical lesson for AI users is to separate “can the model generate content?” from “can that output reach real systems?” If developers connect a model to code, browsers, databases, email or deployment permissions, each tool needs least privilege, audit trails, human approval and revocation. Security teams also need to detect long-running agent behavior. Anthropic’s cases do not prove every platform has the same incidents, but they show why AI safety cannot be reduced to adding one refusal sentence in a chat window.

Read Anthropic’s official Threat Intelligence report