All posts
AI / News

Anthropic's Latest Threat Report Names the Groups Trying to Weaponise Claude

Anthropic: September 2026 threat intelligence report

Anthropic has published its most detailed threat intelligence report yet, and it names names. The report covers activity the company disrupted between December 2025 and August 2026, across seven categories of misuse: cyber operations, influence campaigns, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation.

The specifics are blunt. A Russian state linked group, tracked as GTG-20006, used Claude to automate cyber espionage against Ukrainian and European government targets. A financially motivated crew linked to the ShinyHunters brand used Claude to help orchestrate data breaches across dozens of organisations within hours rather than weeks. A separate Chinese speaking group, GTG-10007, ran an autonomous vulnerability research operation that Anthropic says generated multiple zero day exploits a month.

The report also documents nine influence operations, run out of Russia, Iran, Turkey and elsewhere, targeting elections in Moldova, Malaysia and Kenya. In each case, attackers used Claude to draft convincing copy, build fake profiles and, in some cases, stand up entire fake news sites while concealing who was really behind them.

One detail stands out for anyone building on top of AI tools: attackers are now targeting the supply chain itself. Threat actors stole API keys to fuel secondary attacks and resold access through fraudulent reseller networks, treating a compromised Anthropic account the way criminals used to treat a stolen credit card number.

Anthropic says it disrupted every operation named in the report and shared intelligence with authorities and industry partners where it made sense to. That is the point of publishing this kind of detail at all. A generic warning that AI can be misused tells a security team nothing useful. Naming the actors, the techniques and the specific harm areas gives other labs, and the clients we build for, something to actually check their own systems against.

For a studio that increasingly wires AI into client tools rather than just using it to write copy, the report is a reminder that access control matters as much as the model itself. An API key with broad permissions is worth stealing whether the model behind it is Claude, Gemini or another provider entirely. If a report like this shows anything, it is that attackers are already treating AI credentials as infrastructure worth targeting, so the people building on that infrastructure should too.