返回新聞
安全性AI Understanding 簡報

Anthropic 表示,基於 Claude 的攻擊正在網路犯罪中蔓延

Anthropic 表示,2025 年 12 月至 2026 年 8 月期間,威脅行為者使用 Claude 進行網路破壞、間諜活動、詐欺、監視、武器和生物濫用行動。

4 min readRead the primary source
Source-provided image accompanying Anthropic says Claude-enabled attacks are spreading across cybercrime
主要來源文件來源記錄
出版商
anthropic.com
來源連結
anthropic.comhttps://www.anthropic.com/threat-intelligence-report-september-2026
來源類型
主要文件-我們直接閱讀的官方公告、文件、文件或第一方頁面。
背景60 秒內了解這一點

從這裡開始

關鍵術語

蒸餾
將知識從大型教師模式壓縮到較小的學生模式。
測試一下自己AI 代理測驗

發生了什麼事

Anthropic published a threat-intelligence report describing malicious use of Claude across seven harm areas. The company says suspected state-backed groups, criminals, spyware vendors, propaganda institutions and politically motivated individuals used Claude Haiku, Sonnet and Opus in operations involving cyberattacks, surveillance, fraud, influence activity, conventional weapons, biological misuse and model . Anthropic says it disrupted the activity and used the findings to improve safeguards, but the report is the company’s account and is not independently verified here.

Anthropic says the activity occurred from December 2025 through August 2026 and involved Claude Haiku, Sonnet and Opus. It says no misuse cases involved Claude Fable or Mythos-class models except for one illicit case. The company characterizes the examples as unusually notable rather than representative of all misuse.

The report describes a suspected Russian state-linked operation that allegedly used Claude-assisted workflows to manage phishing, infrastructure, persistence, data exfiltration and malware redevelopment. Anthropic says more than 20 organizations were targeted, including Ukrainian and European government, diplomatic, defense and drone-sector organizations. It also describes alleged compromises involving hotel Wi-Fi providers, messaging accounts, camera-streaming systems and government databases.

Anthropic separately describes financially motivated activity that it associates with affiliates of the ShinyHunters collective. The company says one operator automated the harvesting and analysis of Android applications and credentials, while related intrusions allegedly exposed national identifiers, payment-card data and passenger records. These are claims in Anthropic’s report; the source does not provide independent forensic validation in the supplied text.

The report says Anthropic disrupted the activity, strengthened safeguards and shared information with authorities and industry partners where appropriate. It does not announce a new Claude product, access policy or pricing change.

來源詳情: anthropic.com ↗

為什麼這很重要

The report’s central claim is that AI is lowering the expertise, labor and tooling required for complex cyber operations. Anthropic says attackers used Claude within multi-agent workflows for reconnaissance, phishing, exploitation, data theft and repeated malware modification, allowing some campaigns to operate faster and across more targets. If independently corroborated, that would make attacker sophistication a less reliable attribution signal and increase pressure on defenders to move beyond static detection methods.

The practical significance is the reported combination of model capability with orchestration. Anthropic says humans generally selected targets and reviewed stolen data, while AI systems handled parts of reconnaissance, exploitation, infrastructure setup and monitoring. That distinction matters because the threat is not presented as fully autonomous hacking, but as a reduction in the number of skilled people and hours needed to sustain campaigns.

Anthropic argues that AI can help attackers repeatedly alter tools after security products detect them, potentially shortening the period in which conventional signatures remain effective. The report therefore points toward greater importance for layered controls such as credential protection, rapid patching, behavior-based detection, network segmentation and monitoring for unusual automation.

The evidence remains limited by provenance. The source is a disclosure by the company whose model was allegedly used, and it provides selected case studies rather than a prevalence study. It does not establish how much of the reported harm would have occurred without Claude, whether all attribution claims are correct, or how often safeguards prevented attempted misuse.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

接下來看什麼

Watch for independent confirmation of the reported intrusions, the extent of actual victim harm, and whether other AI providers are observing similar operational patterns. The report does not establish that every described operation succeeded because of Claude, nor does it quantify Claude’s contribution against non-AI alternatives. It also announces no new user-facing access, pricing or availability changes.

Independent threat-intelligence reports, victim disclosures and government investigations could confirm or challenge Anthropic’s attribution and estimates of stolen data. Particular attention should go to the alleged targeting of Ukrainian organizations, drone-related supply chains, diplomatic systems and government identity databases.

Security teams should assess whether their controls can detect automated reconnaissance, credential abuse, rapid infrastructure changes and repeated modification of suspicious tools. The source’s practical warning is that defenders may need to measure attacker behavior across an entire campaign rather than rely only on known malware signatures.

Further reporting may clarify the biological-misuse and conventional-weapons cases referenced by the report’s overview but not detailed in the supplied excerpt. The source also leaves unclear how Anthropic measured AI uplift, how many operations were stopped before victim impact, and whether the safeguards described are available to other developers.

相關指引和測驗

人工智慧代理AI 倫理人工智慧模型解釋測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?