Anthropic September 2026 Threat Report: AI Misuse Across Cyber Operations, Surveillance and Weapons

Anthropic has shared its September 2026 Threat Intelligence Report, “Detecting and countering misuse of AI,” documenting operations disrupted between December 2025 and August 2026 across seven core harm domains.

The report finds that large language models are increasingly being embedded into autonomous, multi-agent frameworks that can execute complex tasks at machine speed. This shift has reduced the labor and tooling gap between major nation-states and lower-resource actors.

Autonomous Cyber Operations and Exploit Foundries

The report highlights the growing use of agentic AI across cyber operations, with adversaries increasingly delegating multiple stages of attacks to AI systems. Human involvement is often limited to selecting targets and reviewing final results.

  • Russian State Espionage (GTG-20006 / Midnight Blizzard): Over 130 days, 24 of 27 targeted institutions, including Ukrainian ministries, defense bodies and drone supply-chain manufacturers, were engaged. AI agents monitored deployed malware and recompiled code when it was detected. The operation also involved hotel guest Wi-Fi networks and the exfiltration of more than 300,000 North African national ID records.
  • Opportunistic Extortion (GTG-50014 / ShinyHunters): Affiliates completed cloud compromises in as little as two to three hours. One operator used 10 AWS EC2 workers to process 1.8 million Android APKs, while another extracted more than 2,100 Azure AD tokens across over 40 corporate tenants in 34 hours.
  • Continuous Zero-Day Foundries (GTG-10007): China-based actors automated security appliance firmware analysis and identified more than a dozen potential zero-day vulnerabilities in one month across roughly 50 global targets.
  • AI Supply Chain Attacks (GTG-50020 & GTG-50021): One operation targeted 30 AI firms in four days while seeking pre-release models and production API keys. Another operated fraudulent AI reseller services that proxied traffic to other models while harvesting Anthropic account credentials.
  • Political Hacktivism (GTG-50029): A French actor breached 14 of 42 targeted entities and compiled a dark-web doxxing engine containing tens of millions of records.

Anthropic also identified formalized attack procedures using Claude Code personas and persistent-memory frameworks, including /security-engineer, shadow_c2 and iOS Safari exploit modules.

Influence Operations

AI was integrated into influence operations for content production, account management, audience targeting and impersonation. The campaigns covered multiple regions and used large numbers of generated articles, social posts and synthetic accounts.

  • LKM Company (GTG-54002): Published 8,913 articles across around 70 sites in 20 languages and amplified them through more than 250 fake X accounts, reaching audiences across six continents.
  • BBS Bilisim (GTG-84005): Managed more than 1,000 accounts and used national census records to micro-target ethnic, religious and royal fault lines across all 222 Malaysian districts.
  • State Desks (GTG-24015, GTG-04001): Operations linked to RT, Sputnik, RIA Novosti and Radio Lengo Songo used AI to score staff loyalty and produce state-aligned messaging, including election claims involving Moldova and pro-Wagner messaging in the Central African Republic.
  • Impersonation and Astroturfing: Other campaigns cloned activist communication styles, generated batches of headlines and social posts, supported covert recruitment in Iran and produced ghostwritten political messaging.
Surveillance Operations

The report also documents AI-assisted surveillance operations that processed large volumes of communications and online activity. These systems were used by state security bodies and commercial vendors to profile populations, monitor dissidents and organize intelligence.

  • Mali ANSE (GTG-50027): Developed the “Lakana 360” platform for automated communications analysis covering 25 million national mobile SIM cards.
  • Commercial Vendor (GTG-54009): Used demographic categorization and synthetic accounts to profile Iranian and Persian Gulf diaspora populations.
  • PRC Security Bureaus (GTG-14010, GTG-14020, GTG-14021, GTG-14022): Generated 2,475 investigative briefs in 30 days covering dissidents, Uyghurs in Syria, pro-democracy protests in Vancouver and Asian religious figures.
  • Iranian Units (GTG-34007, GTG-30004, GTG-30005, GTG-30006): Used spyware and other data-extraction tools while analyzing 155,216 tweets and producing open-source intelligence related to US naval fleet positions.
Conventional Weapons

AI was also incorporated into weapons engineering, autonomous drone systems, electronic warfare and military procurement. The operations documented by Anthropic ranged from engineering analysis to the development of autonomous systems and military research.

A Yemen-based GNC cell (GTG-87001) integrated flight software onto a phone-class computer and used Claude for post-launch analysis involving a tactical guided rocket. Drone-related operations (GTG-27005) developed fault-tolerant logic and vision guidance for autonomous FPV systems, with target classification trained on Ukrainian combat footage.

Other operations included a 200+ page Chinese naval anti-torpedo proposal and a 16-module electronic warfare suite. AI was also used to model radar suppression against 12 Taiwanese targets, including Patriot and THAAD systems, and to automate military procurement and map directed-energy weapon supply chains.

Biological Misuse and Scaled Fraud

Anthropic said its biological safety systems successfully blocked direct bioweapons construction prompts. However, researchers in unsupported regions used proxy networks to route dual-use scientific queries through other systems, including research involving pathogens, immune evasion and other high-risk biological topics.

The report also identified a China-based dating-app fraud operation that used more than 4,700 automated Claude personas across over 20 applications. These personas exchanged 2.36 million messages with 25,000 users over two weeks, while real gig workers were used alongside the AI personas to maintain interactions.

Illicit Distillation by Competitor AI Labs

Anthropic identified systematic attempts by several AI laboratories to harvest information from its models through large-scale proxying and replay of interactions. The report said these operations involved millions of exchanges and, in some cases, exposed sensitive information contained in the processed data.

  • Alibaba (GTG-16005): Generated more than 151 million exchanges across 3,500+ accounts, reaching nearly 3 million exchanges per day, to support training of Qwen models.
  • Moonshot AI and DeepSeek (GTG-16002 & GTG-16001): Proxied more than 23 million and 12.1 million exchanges, respectively, to Claude Opus.
  • Zhipu AI (GTG-16006): Targeted Opus 4.6 for cyber reasoning across more than 3.4 million exchanges.
  • Xiaomi, SenseTime and MiniMax: Xiaomi replayed more than 400,000 developer sessions through 1,500 accounts, SenseTime obtained harvested user transcripts from data brokers, and MiniMax operated an unbranded proxy to collect multi-turn developer prompts.
Threat Landscape Outlook

Anthropic said the threat environment has shifted from interactive chat abuse toward autonomous agentic execution. The report highlights a lower cost of conducting large-scale cyber campaigns, surveillance operations and weapons-related engineering, while the broader AI supply chain is becoming both an attack surface and a source of computing resources.

The report argues that static keyword blocking and isolated account suspensions are insufficient against distributed, multi-agent threats. Anthropic points to architectural safeguards, stronger API identity controls, real-time threat sharing between model providers and verified trusted-access programs for high-risk scientific disciplines.


Related Post