Anthropic on Thursday published its September 2026 threat intelligence report, "Detecting and countering misuse of AI," describing how its Threat Intelligence team identified and disrupted threat actors that misused Claude between December 2025 and August 2026. The cases span seven distinct harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit model distillation. According to the company, every campaign it describes was disrupted, and intelligence was shared with authorities and industry partners where appropriate.

The report lands at a moment of intense scrutiny for the AI industry, and for Anthropic in particular, as breaking AI news this week has been dominated by safety disclosures, whistleblower accounts, and mounting pressure from lawmakers. It also arrives alongside reporting from The New York Times and Politico highlighting attempts to weaponize frontier models — including blocked efforts related to biological weapons development.

How Anthropic Tracks AI-Enabled Threat Actors

Anthropic tracks the actors in its report under internal designators known as Generative Threat Groups, or GTGs. Each case study measures what the company calls uplift — the capability boost that AI gives an operation across three dimensions: speed, scale, and depth. The misuse cases involved Claude Haiku, Sonnet, and Opus models. None involved the company's Fable or Mythos-class models, with the exception of one illicit distillation case.

Anthropic frames its willingness to publish as a duty rather than a marketing exercise, stating in the report that "we believe we have a responsibility to disclose malicious misuse of our services."

A Midnight Blizzard-Linked Operation That Rebuilt Its Own Malware

The report's most extensive cyber case, tracked as GTG-20006, describes an actor whose attribution Anthropic says is consistent with public reporting linking it to Midnight Blizzard, the Russian state-aligned hacking group formerly known as Nobelium or APT29. One of its operators, an individual using the handle "JackPoterz," is a Russian speaker.

According to the report, the group targeted more than 20 organizations, concentrated among Ukrainian government, military, and diplomatic bodies. It compromised at least three hotel WiFi vendors to hijack DNS records, took over the WhatsApp accounts of at least two former high-level Ukrainian officials, and stole more than 300,000 national identity records along with commercial registry data covering more than half a million companies from a North African government technology authority.

The most striking detail is autonomous adaptation: Anthropic reports that the actor's AI agents modified and rebuilt the group's malware whenever security products detected it — a loop that previously would have required skilled developers on demand.

Credential Harvesting at Scale and Autonomous Zero-Day Hunting

A second case, GTG-50014, covers operators suspected of affiliation with the ShinyHunters collective. Their credential-harvesting pipelines mass-downloaded 1.8 million Android APKs and scanned them for hardcoded secrets. In one compromise of a technology provider, more than a terabyte of data was exfiltrated, including millions of payment card records. Another affiliate extracted data from roughly 200 downstream customers of a breached software-as-a-service provider and dumped more than 2,100 Azure AD token sets spanning over 40 corporate tenants in about 34 hours — with AI agents performing nearly all of the work, per the report.

GTG-10007 is more sobering still for defenders. Anthropic attributes this cluster to Chinese-speaking operators likely based in Changsha, Hunan — two of whom it identified as undergraduate students — who targeted roughly fifty organizations and ran an autonomous vulnerability research program. One workflow, iterating on network appliances, yielded more than a dozen possible zero-day findings in a single month.

Extortion, a Lone Hacktivist, and a Failed Raid on AI Labs

Financially motivated misuse features prominently. GTG-50020, a Russian-speaking actor, exfiltrated roughly 26 gigabytes from one victim and sought between $1.5 million and $2.5 million in extortion. The same group then attacked roughly thirty AI companies in about four days with the stated goal of accessing a pre-release Claude model. Anthropic says every attempted path failed and its own systems were never compromised.

At the other end of the spectrum, GTG-50029 was a single French-speaking hacktivist who exploited a previously undocumented WordPress re-installation race condition against at least four sites, gained internal access to at least 14 of 42 tracked targets, and exfiltrated approximately 140,000 records — including users' political opinions from a campaign platform. The actor then built a doxxing platform, fafsearch, loaded with tens of millions of rows.

Influence Operations From the Central African Republic to Malaysia

Nine influence operation cases in the report originated in Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe, with reach measured on the Brookings Institution's Breakout Scale. In one case, GTG-04001, a Russian-speaking actor based in Bangui produced daily content for Radio Lengo Songo, a station Anthropic linked to Politology — the Africa Corps and Wagner influence branch that it assesses came under Russian Foreign Intelligence Service control in late 2023. The operation produced forged Central African Republic government documents and employment contracts mandating loyalty to the country's president and to Russia, and was assessed as Category Four on the scale.

Another network, GTG-54002, was traced to LKM Company, a France-based digital advertising agency operating roughly 70 fabricated news websites, 70 matching X accounts, and more than 250 inauthentic commenting accounts. The network published at least 8,913 articles in about 20 languages, 318 of them focused on the Democratic Republic of Congo.

Elections were also a target. GTG-84005, a commercial election-manipulation platform aiming at Malaysia that Anthropic linked to Istanbul-based BBS Bilisim Teknolojileri, managed about 1,000 fake X accounts across all 222 Malaysian parliamentary constituencies and fabricated dossiers against an opposition politician. A separate cluster, GTG-24015, used four accounts as an AI-assisted editorial desk feeding Russian state media.

Why Disclosure Matters

Anthropic says it disrupted the activity in each case, used the findings to strengthen its safeguards, and shared intelligence with authorities and industry partners where appropriate. Publishing detailed case studies — complete with failure analyses of its own detections — remains rare among frontier labs, and the company argues that transparency raises the baseline for the entire industry.

The report also underscores a shift that security teams can no longer ignore: the most dangerous AI-enabled operations described here were not hypothetical demonstrations but live campaigns against governments, companies, and elections. As models grow more capable, Anthropic's data suggests the uplift they provide to determined adversaries is compounding — and the defenders' best available answer, for now, is visibility, disclosure, and faster iteration on safeguards.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →