Anthropic's September 2026 threat report describes AI-run espionage, ransomware and influence operations

Anthropic published its September 2026 threat intelligence report on September 10, 2026, covering malicious use of Claude that its Threat Intelligence team detected and disrupted between December 2025 and August 2026 across seven harm categories. The framing sentence is the one worth quoting to a board: “sophisticated attacks no longer require sophisticated attackers.” The report’s argument is that AI has compressed the labor and expertise gap enough that a single operator can now run multi-victim campaigns that previously needed a team of specialists.

The cyber cases are the sharpest. A Russian espionage cluster Anthropic tracks as GTG-20006 targeted more than 20 organizations including Ukrainian government bodies, military units and drone manufacturers, and used Claude to autonomously rebuild and redeploy its malware whenever a security product detected it - a technique Anthropic describes as inverting costs back onto defenders. A separate operation compromised more than 300,000 national identity records and a half-million-entry company registry in North Africa. A criminal group tracked as GTG-50014 breached an airline, an energy company and a technology provider, exfiltrating over a terabyte in one case and moving from first access to bulk data theft in hours, and treated the AI supply chain itself as both target and resource by stealing victims’ API keys to fund further attacks. A Chinese cluster, GTG-10007, stood up an autonomous vulnerability research program against roughly 50 organizations that produced multiple previously unknown vulnerabilities through continuous binary-reversing workflows.

The influence operations are less dramatic but arguably more instructive about where this goes commercially. One commercial influence-as-a-service operation ran roughly 70 fabricated news websites, 70 X accounts and more than 250 inauthentic commenting accounts across six continents, rewriting legitimate journalism in opposite ideological directions for different audiences; Anthropic attributes it to a France-based advertising agency. Another built a constituency-targeting system for Malaysian election manipulation from real census and voter data, running roughly 1,000 fake accounts, attributed to an Istanbul-based technology company. In a Central African Republic case, Claude was used to write HR infrastructure that encoded political compliance into employment contracts.

Anthropic says it banned the identified accounts and organizations, shared indicators of compromise with industry and government, and deployed behavioral detection for the tactics involved. The honest reading for a leader is narrower than the headlines will be. This is one vendor’s account of misuse of its own product, published by the vendor, with no independent verification of attribution - and it necessarily says nothing about the same campaigns run on models that do not publish reports. What it does establish concretely is the division of labor that has settled in: humans still pick targets, handle monetization and review results, while the model does reconnaissance, exploitation, data processing and tool development at machine speed and in parallel.

Sources

Last verified September 14, 2026