Anthropic’s Threat Intelligence team has released a report detailing the identification and disruption of operations in which threat actors misused Claude for malicious purposes between December 2025 and August 2026. The report covers activity across seven harm categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.

According to the report, threat actors using Claude included suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. The misuse cases involved Claude Haiku, Sonnet, and Opus models, with one exception—an illicit distillation case involving Claude Fable or Mythos-class models. The cases documented range from networks of fake dating apps designed to defraud users to surveillance systems built to identify and monitor dissidents.
A key finding from the report is that AI adoption has “collapsed the labor and tooling gap” that previously separated well-resourced, state-sponsored operations from individual operators. Anthropic’s analysis indicates that sophisticated attacks no longer require sophisticated attackers. The cybersecurity skills of AI models mean that a hacktivist using stolen API keys, disparate financially motivated individuals, and state espionage operators have each sustained multi-victim campaigns that would have required many skilled operators and specialist knowledge just a year ago.
The report identifies several trends in AI-augmented cyber operations. Sophistication has stopped being a reliable signal of who is behind an operation, as every layer of offensive operations—from reconnaissance and tool development to data processing and exploitation—has been enhanced by AI. Publicly available offensive agent frameworks like PentAGI have proliferated this scaffolding across multiple classes of actors.
Another significant trend documented is that AI’s role in cyber operations has become increasingly autonomous. A majority of the operations described involved AI via direct execution or orchestration, using multi-agent frameworks to execute reconnaissance, exploitation, and data exfiltration, with humans remaining in the loop primarily to set attack targets and review exfiltration.
One case study detailed is GTG-20006, attributed as a Russian espionage actor consistent with public reporting linking the group to Midnight Blizzard. This actor automated their operations using AI-driven workflows, increasing their speed and threatening defenders’ ability to impose costs through static detections alone. The actor targeted military intelligence, diplomatic, and defense organizations and individuals connected to U.S. foreign policy.
In response to these threats, Anthropic states it has disrupted each case, used findings to strengthen safeguards, and shared intelligence with authorities and industry partners where appropriate. The company emphasizes that as models become increasingly capable, their risks will increase unless AI developers and society’s defenders act to make them safer.
Key facts
- Anthropic disrupted malicious operations spanning seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation between December 2025 and August 2026
- Threat actors included state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals
- AI adoption has reduced the skill and resources required for sophisticated cyber attacks, enabling individual operators to conduct campaigns previously requiring many skilled specialists
- A majority of disrupted operations used multi-agent AI frameworks for autonomous reconnaissance, exploitation, and data exfiltration, with humans setting targets and reviewing exfiltration
- Russian espionage actor GTG-20006 used AI-driven workflows to automate toolkit development, deployment, and rebuilding when detected by security products
