A new Anthropic threat intelligence report reveals how criminals, hacktivists and state-backed operators are using Claude to run cyberattacks, espionage and disinformation campaigns once reserved for well-resourced intelligence services.
Anthropic has published its latest threat intelligence report, detailing how threat actors attempted to misuse its Claude AI models between December 2025 and August 2026. The findings, spanning cyber operations, espionage, disinformation and fraud, suggest that artificial intelligence is eroding the traditional gap between sophisticated, state-sponsored attackers and low-resourced individual operators.
According to the company, its Threat Intelligence team identified and disrupted a range of operations across seven harm categories, including cyber operations, surveillance, influence campaigns, fraud, biological misuse, conventional weapons development and model distillation. Anthropic states that Claude Haiku, Sonnet and Opus models were implicated, while its newer Fable and Mythos-class models were involved in only a single distillation case.
The report’s central finding is that AI has “inverted the cost” long imposed on attackers by defenders. Where sophisticated intrusions once required teams of skilled operators, Anthropic now describes cases in which individuals ran multi-victim campaigns largely through autonomous AI agents.
One case study, tracked internally as GTG-20006, involves an actor whose tradecraft the company links to the Russian state-nexus group publicly known as Midnight Blizzard. According to the report, the group used AI-driven workflows to build phishing infrastructure, manage malware, and automatically rebuild tools once security products flagged them — targeting Ukrainian government, military and drone-supply-chain organizations, alongside diplomatic missions across Europe, the Middle East and Asia.
A second cluster, GTG-50014, is attributed to affiliates of the ShinyHunters extortion collective. Anthropic describes a French-speaking operator running a credential-harvesting pipeline across ten cloud servers that scanned 1.8 million Android app files for exposed secrets, feeding a Telegram-based criminal marketplace. Other affiliates reportedly compromised a technology provider, an airline and an energy company, in one case exfiltrating more than a terabyte of data in a single supply-chain breach.
A third operation, GTG-10007, is linked to Chinese-speaking operators the company says were based in Hunan province, including university students. Anthropic reports that the group ran continuous, largely unattended AI workflows for vulnerability research against security appliances, alongside reconnaissance against foreign government networks and an intelligence-collection platform.
The report also highlights the AI supply chain itself as a target. Anthropic describes GTG-50020, a financially motivated actor that pivoted from hotel-booking fraud to attacking AI vendors directly, at one point using prompt injection against an evaluation sandbox to steal production API keys. The company states the actor’s ultimate goal — gaining access to a pre-release Claude model — was never achieved.
On the disinformation side, Anthropic details nine influence operations originating in Russia, Iran, Turkey and elsewhere. These include a Russian mercenary Wagner propaganda network in the Central African Republic broadcast via a Bangui radio station; a French advertising agency running roughly 70 fabricated news outlets across six continents; a Turkish company selling a Malaysia-focused “military-grade” election-manipulation platform to clients; and Iranian state institutions using Claude to draft doctrine, personas and ministerial planning documents as part of what they termed a “cognitive warfare” program.
Anthropic states it banned the accounts involved in each case, shared indicators of compromise with industry and government partners, and used the findings to refine its detection systems. The company notes that in several instances, Claude itself declined the most aggressive requests — including naming real individuals as militants or fabricating defamatory dossiers — forcing actors to negotiate softer phrasing instead.
The report concludes that sophistication is no longer a reliable signal of who is behind an attack, since AI has made advanced tradecraft accessible to lone individuals and small groups alike. Anthropic says it will continue publishing such findings to help other AI developers, governments and defenders recognize similar patterns.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de