Chips & compute
Anthropic says attackers used Claude to run whole cyberattacks
A September threat report details Russia- and China-linked campaigns and accuses seven Chinese labs of harvesting Claude's answers.
The answer
Anthropic disrupted misuse where Claude ran multiple stages of cyberattacks, it said.
Anthropic published its fourth threat intelligence report on 10 September 2026, detailing misuse of its Claude models that its team detected and stopped between December 2025 and August 2026. Anthropic said attackers increasingly used Claude not just for advice or code, but as an orchestrator across several stages of an attack.
The report covers cyber operations, influence operations, surveillance, scams and fraud, weapons-related misuse and illicit model distillation, the practice of copying a model by training on its answers.
In one case, a Russia-linked espionage group tracked as GTG-20006, with activity consistent with Midnight Blizzard, used Claude to automate reconnaissance, malware development and the rebuilding of tools after detection, Anthropic said. The group targeted more than 20 organisations including drone makers and Ukrainian officials, and its agents monitored security products and rewrote malware in a loop until it evaded detection.
A separate China-based operation, GTG-14010, used Claude to convert chatter from more than 100 monitored WhatsApp groups and dozens of Telegram channels into structured data to track Uyghurs in Syria, Anthropic said. The group also used Claude to draft restricted briefings cataloguing dissidents and diaspora communities.
Anthropic accused seven Chinese labs, Alibaba, DeepSeek, Moonshot, Xiaomi, Zhipu, SenseTime and MiniMax, of using thousands of fraudulent accounts to harvest Claude's responses for training, a practice known as distillation.
The report also described nine influence campaigns originating from Turkey, Iran, Russia and elsewhere, the criminal group ShinyHunters using Claude to speed up scanning and system takeovers, and two Chinese undergraduates running an automated exploit "foundry". Anthropic said all accounts involved in the cases it identified were banned.
Anthropic said the cases it documented involved older Claude Haiku, Sonnet and Opus models rather than its Fable or Mythos-class systems, with one exception among the distillation cases. Further details are set out in Anthropic's full report and were also covered by Reuters via US News.
Sources
- Countering misuse of AI: September 2026 — Anthropic, 10 September 2026
- Anthropic disrupts Russian, Chinese AI campaigns targeting its Claude models — Reuters via US News, 10 September 2026