Back to News
SecurityAI Understanding briefing

Anthropic says Claude-enabled attacks are spreading across cybercrime

Anthropic says threat actors used Claude in disrupted cyber, espionage, fraud, surveillance, weapons and biological-misuse operations between December 2025 and August 2026.

4 min readRead the primary source
Source-provided image accompanying Anthropic says Claude-enabled attacks are spreading across cybercrime
Primary-source documentSource recorded
Publisher
anthropic.com
Source link
anthropic.comhttps://www.anthropic.com/threat-intelligence-report-september-2026
Source type
Primary document — an official announcement, paper, filing, or first-party page we read directly.
ContextUnderstand this in 60 seconds

Start here

Key terms

Distillation
Compressing knowledge from a large teacher model into a smaller student model.
Test yourselfAI Agents Quiz

What happened

Anthropic published a threat-intelligence report describing malicious use of Claude across seven harm areas. The company says suspected state-backed groups, criminals, spyware vendors, propaganda institutions and politically motivated individuals used Claude Haiku, Sonnet and Opus in operations involving cyberattacks, surveillance, fraud, influence activity, conventional weapons, biological misuse and model distillation. Anthropic says it disrupted the activity and used the findings to improve safeguards, but the report is the company’s account and is not independently verified here.

Anthropic says the activity occurred from December 2025 through August 2026 and involved Claude Haiku, Sonnet and Opus. It says no misuse cases involved Claude Fable or Mythos-class models except for one illicit distillation case. The company characterizes the examples as unusually notable rather than representative of all misuse.

The report describes a suspected Russian state-linked operation that allegedly used Claude-assisted workflows to manage phishing, infrastructure, persistence, data exfiltration and malware redevelopment. Anthropic says more than 20 organizations were targeted, including Ukrainian and European government, diplomatic, defense and drone-sector organizations. It also describes alleged compromises involving hotel Wi-Fi providers, messaging accounts, camera-streaming systems and government databases.

Anthropic separately describes financially motivated activity that it associates with affiliates of the ShinyHunters collective. The company says one operator automated the harvesting and analysis of Android applications and credentials, while related intrusions allegedly exposed national identifiers, payment-card data and passenger records. These are claims in Anthropic’s report; the source does not provide independent forensic validation in the supplied text.

The report says Anthropic disrupted the activity, strengthened safeguards and shared information with authorities and industry partners where appropriate. It does not announce a new Claude product, access policy or pricing change.

Source details: anthropic.com

Why it matters

The report’s central claim is that AI is lowering the expertise, labor and tooling required for complex cyber operations. Anthropic says attackers used Claude within multi-agent workflows for reconnaissance, phishing, exploitation, data theft and repeated malware modification, allowing some campaigns to operate faster and across more targets. If independently corroborated, that would make attacker sophistication a less reliable attribution signal and increase pressure on defenders to move beyond static detection methods.

The practical significance is the reported combination of model capability with orchestration. Anthropic says humans generally selected targets and reviewed stolen data, while AI systems handled parts of reconnaissance, exploitation, infrastructure setup and monitoring. That distinction matters because the threat is not presented as fully autonomous hacking, but as a reduction in the number of skilled people and hours needed to sustain campaigns.

Anthropic argues that AI can help attackers repeatedly alter tools after security products detect them, potentially shortening the period in which conventional signatures remain effective. The report therefore points toward greater importance for layered controls such as credential protection, rapid patching, behavior-based detection, network segmentation and monitoring for unusual automation.

The evidence remains limited by provenance. The source is a disclosure by the company whose model was allegedly used, and it provides selected case studies rather than a prevalence study. It does not establish how much of the reported harm would have occurred without Claude, whether all attribution claims are correct, or how often safeguards prevented attempted misuse.

What to watch next

Watch for independent confirmation of the reported intrusions, the extent of actual victim harm, and whether other AI providers are observing similar operational patterns. The report does not establish that every described operation succeeded because of Claude, nor does it quantify Claude’s contribution against non-AI alternatives. It also announces no new user-facing access, pricing or availability changes.

Independent threat-intelligence reports, victim disclosures and government investigations could confirm or challenge Anthropic’s attribution and estimates of stolen data. Particular attention should go to the alleged targeting of Ukrainian organizations, drone-related supply chains, diplomatic systems and government identity databases.

Security teams should assess whether their controls can detect automated reconnaissance, credential abuse, rapid infrastructure changes and repeated modification of suspicious tools. The source’s practical warning is that defenders may need to measure attacker behavior across an entire campaign rather than rely only on known malware signatures.

Further reporting may clarify the biological-misuse and conventional-weapons cases referenced by the report’s overview but not detailed in the supplied excerpt. The source also leaves unclear how Anthropic measured AI uplift, how many operations were stopped before victim impact, and whether the safeguards described are available to other developers.

Related guides & quizzes

AI AgentsAI EthicsAI Models ExplainedTest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?