Anthropic Reports AI-Assisted Cyberattacks and Other Misuse of Claude

anthropic claude ai cyber attacks

AI Assistants · Sep 22, 2026 · By Manish sharma

  • Anthropic says threat across used Claude to automate parts of cyber operations, including vulnerability research and exploitation

  • A Russia-linked operation allegedly used AI to accelerate espionage against organizations in Ukraine and Europe. 

  • The company also reported misuse involving surveillance, influence campaigns, fraud, and other harmful activities. 

Sep 11, 2026 - Anthropic has released a new threat intelligence report detailing how malicious actors used its Claude AI models for cyberattacks, espionage, surveillance, fraud, and other activities between December 2025 and August 2026. The company said it disrupted the operations it identified and shared relevant intelligence with authorities and other organizations. 

One of the cases involved an actor tracked by Anthropic as GTB-20006, which the company said showed characteristics consistent with the Russian state-linked group Midnight Blizzard. The operation targeted military intelligence organizations in Ukraine and Europe, as well as diplomatic and defence-related organizations and people connected to U.S. foreign policy. 

Anthropic said the group used AI to automate parts of its operations, allowing attackers to work faster and reduce the amount of manual effort required. The company said the development represents a shift in how threat actors can use AI to scale cyber operations. 

The report also describes several cases in which AI agents were used for vulnerability research and exploit development. According to Anthropic, some actors created automated workflows that directed Claude to investigate vulnerabilities, test potential exploits, and continue research with limited human behavior. 

Another case involved a financially motivated Russian-speaking actor that moved from attacks on hotel booking and financial technology systems to targeting an AI company. Anthropic said the actor manipulated an automated evaluation environment and obtained credentials, including production API keys belonging to multiple API providers. 

The report covers more than cyber operations. Anthropic identified cases involving political influence campaigns, surveillance, and fraud, including operations that used large numbers of AI-generated personas to interact with real users. The company said the incidents originated from actors in several regions and targeted audiences across multiple continents. 

The findings add to growing concerns among cybersecurity researchers about AI agents being used as operational tools rather than merely assistants. Anthropic has separately reported incidents in which Claude models gained unauthorized access to third-party systems during evaluations, highlighting the difficulty of controlling increasingly capable systems when they can interact with external services. 

Sources:

https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents

https://www.anthropic.com/threat-intelligence-report-september-2026