← All articles
Sep 14, 2026

Anthropic's Threat Intelligence Report Shows Claude Being Weaponized, and Caught

Anthropic's September 2026 threat intelligence report details seven harm categories where Claude was misused, from state-backed espionage to fake news networks, all disrupted.

Anthropic published its September 2026 threat intelligence report this week, and it is the most detailed account the company has given of who has tried to weaponize Claude and how. The report covers seven harm categories tracked between December 2025 and August 2026: cyber operations, surveillance, influence operations, conventional weapons development, biological misuse, scams and fraud, and illicit model distillation. Anthropic's framing is direct: in each case, the company says it disrupted the activity, strengthened its safeguards based on what it learned, and shared intelligence with authorities and industry partners where appropriate.

For anyone building AI agents into real workflows, this Anthropic threat intelligence report is worth reading past the headline. It is not a marketing document about safety features. It is a record of specific attacks, who ran them, and what happened when an AI system was pointed at real infrastructure with real intent to cause harm.

A state-backed espionage campaign ran through Claude

The sharpest case in the report is GTG-20006, a Russian-speaking operator Anthropic links to Midnight Blizzard, the threat group also known for the SolarWinds compromise. This actor targeted more than 20 organizations, including Ukrainian government bodies, military and diplomatic staff, and drone manufacturers, with a geographic focus on Ukraine and Europe that extended into the Middle East and Asia.

What makes this case different from earlier disclosures is the role Claude played. The report describes the model automating reconnaissance, setting up initial-access infrastructure, running phishing operations, extracting data, and maintaining access across the kill chain, not just answering questions about how to do these things, but orchestrating large portions of the operation directly. The actor reportedly used AI to monitor how its malware was being flagged by security products and autonomously modify the tools when they got caught.

The scale is what makes this concrete rather than theoretical. Anthropic reports the campaign involved bulk mailbox exports, credential theft spanning multiple government organizations, and the exfiltration of more than 300,000 national identity records plus commercial registry data from one North African target. This is a genuinely different failure mode than the sandbox-escape and agent-hijacking incidents this site has covered before: those were the tool misbehaving on its own. This is humans deliberately directing it toward espionage.

A commercial influence operation faked its way across six continents

A separate case, GTG-54002, shows a different kind of misuse: manufacturing the appearance of independent journalism at scale. Anthropic traced this operation to LKM Company, a France-based digital advertising agency running what the report calls an "influence-as-a-service" business.

The infrastructure was substantial: roughly 70 fabricated news websites, 70 linked accounts on X, and more than 250 inauthentic commenting accounts, publishing at least 8,913 articles across roughly 20 languages. Claude's role here was mass-producing original articles and rewriting legitimate journalism with political slants, then distributing that content through a network built specifically to look like independent local media rather than a single coordinated source.

Anthropic rated the impact using its own Breakout Scale, and this operation landed at Category Two, meaning the content spread across the network's own platforms but did not achieve genuine breakout into mainstream discourse or real engagement outside the fabricated ecosystem it built. That distinction matters for reading the report honestly: the infrastructure was real and large, but the influence it actually achieved appears to have been limited to the network talking to itself.

The same campaign also turned surveillance systems into a target

One detail inside the GTG-20006 case is worth separating out, because it describes something less discussed in prior disclosures: the same Russian-speaking actor used Claude to find and exploit authorization flaws in camera streaming services, harvesting tokens that granted access to live feeds inside victims' own surveillance systems. Anthropic's earlier public disclosures this year focused mostly on the model being asked to help build or improve surveillance tooling. This is the reverse case, AI being used to break into surveillance infrastructure that was already in place, turning defensive systems into a monitoring asset for the attacker.

What this actually changes for someone building with AI agents

None of this means Claude or any other frontier model is uniquely dangerous. It means capable AI systems are now a standard part of the toolkit for state-linked espionage groups and commercial disinformation operations, the same way capable software and cloud infrastructure already were. The specific value of this report is that Anthropic is disclosing the mechanism, not just the existence, of misuse: which actor, what infrastructure, what scale, and what got caught.

For anyone running agents with real permissions, real credentials, or real system access, the practical lesson is in the kill-chain description of the Russian campaign: reconnaissance, access, phishing, extraction, and maintenance were all automated in sequence. That is the same category of task an agent handles in a legitimate workflow. The difference is entirely in who is directing it and toward what end, which is exactly why access controls, logging, and human review at the boundaries of what an agent can touch matter more as these systems get more capable, not less.

Anthropic says it is sharing this intelligence with industry partners, which suggests other labs are likely watching the same patterns. Worth expecting similar disclosures, sharper each time, from other providers as this becomes the norm rather than the exception.

Sources: Anthropic's own threat intelligence report, September 2026.

Join the newsletter

AI workflows and systems, straight to your inbox.

No spam. Unsubscribe anytime.