No link to story available
In its September 2026 Threat Intelligence Report, Anthropic detailed its ongoing operations to detect, disrupt, and mitigate the malicious misuse of its Claude AI models across seven core harm areas:
Cyber Operations:
Anthropic identified and banned several threat actors, including GTG-20006 (linked to Russia's Midnight Blizzard), which used AI to automate malware re-tooling, phishing, and infrastructure setup. They also disrupted GTG-50014 (ShinyHunters affiliates) conducting opportunistic data theft and extortion, and GTG-10007 (a Chinese-speaking group) that built autonomous "agent swarms" for zero-day exploit research and intelligence harvesting.
Influence Operations:
The team dismantled multiple covert campaigns using AI as a "newsdesk" to launder state propaganda. This included a Russian-led operation in the Central African Republic (GTG-04001), a commercial "influence-as-a-service" platform targeting Malaysia (GTG-84005), Iranian state-aligned networks (GTG-34001), and pro-Awami League fake-news rings in Bangladesh (GTG-54006).
Surveillance Operations:
Anthropic blocked state-aligned actors and spyware vendors from utilizing Claude to build mass-interception software or ingest bulk social media data to profile dissidents, notably targeting Uyghur, Tibetan, and Iranian diaspora communities.
Conventional Weapons:
The company shut down groups using Claude to engineer weapons software, including a Yemen-based cell (GTG-87001) designing guided rocket firmware, and China-nexus actors drafting fire-control specifications for undersea warfare and electronic warfare routing.
Biological Misuse & Scams:
Anthropic intervened against researchers attempting to leverage models for dual-use biological research, such as avian influenza mammalian adaptation and gain-of-function planning. They also terminated a deceptive dating app network (GTG-15001) that deployed over 4,700 AI personas to defraud users.
Illicit Distillation:
Anthropic actively defended its IP against unauthorized industrial-scale campaigns by Chinese AI labs—including Alibaba, DeepSeek, Moonshot, Zhipu, and Xiaomi—which flooded Claude with queries to illicitly harvest its reasoning traces and chain-of-thought data to train competing models.
To counter these evolving threats, Anthropic deployed advanced technical safeguards, including encrypted and summarized internal reasoning, identity verification for high-risk regions, and intelligence sharing with industry peers and global authorities.
https://www.anthropic.com/threat-intelligence-report-september-2026 [anthropic.com]