Anthropic’s September misuse report names specific operations

Anthropic’s latest threat intelligence report sets out in unusual detail how state-linked and criminal groups have been trying to use Claude. Published on 10 September, it covers cases the company says it disrupted between December 2025 and August 2026 across seven categories of harm: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, scams and fraud, and illicit model distillation.

The case studies are specific. A Russian state-linked cluster is described automating intrusions against Ukrainian and European government targets, touching more than twenty organisations with an interest in drone suppliers. A financially motivated group is said to have harvested credentials at scale, including from 1.8 million distinct Android APKs, and in one breach to have moved from a single stolen developer token to full administrative control in roughly three hours. A commercial influence operation ran some seventy fabricated news sites and published 8,913 articles.

Why it matters: every figure here comes from Anthropic’s own detection, none of it can be checked from outside, and a report like this also serves the company’s positioning on safety. Read with that discount applied, it is still one of the few detailed public accounts of how frontier models are being misused in practice.


Related